glyphandcog CVE Vulnerabilities & Metrics

Focus on glyphandcog vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About glyphandcog Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with glyphandcog. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total glyphandcog CVEs: 31
Earliest CVE date: 09 Apr 2009, 15:08 UTC
Latest CVE date: 10 Nov 2022, 18:15 UTC

Latest CVE reference: CVE-2021-40226

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical glyphandcog CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.42

Max CVSS: 10.0

Critical CVEs (≥9): 5

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 45
7.0-8.9 1
9.0-10.0 5

CVSS Distribution Chart

Top 5 Highest CVSS glyphandcog CVEs

These are the five CVEs with the highest CVSS scores for glyphandcog, sorted by severity first and recency.

All CVEs for glyphandcog

CVE-2021-40226 glyphandcog vulnerability CVSS: 0 10 Nov 2022, 18:15 UTC

xpdfreader 4.03 is vulnerable to Buffer Overflow.

CVE-2022-24107 glyphandcog vulnerability CVSS: 0 30 Aug 2022, 04:15 UTC

Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

CVE-2022-24106 glyphandcog vulnerability CVSS: 0 30 Aug 2022, 04:15 UTC

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

CVE-2019-17064 glyphandcog vulnerability CVSS: 4.3 01 Oct 2019, 16:15 UTC

Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

CVE-2019-16927 glyphandcog vulnerability CVSS: 4.3 27 Sep 2019, 20:15 UTC

Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.

CVE-2019-16115 glyphandcog vulnerability CVSS: 6.8 08 Sep 2019, 22:15 UTC

In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.

CVE-2019-16088 glyphandcog vulnerability CVSS: 4.3 06 Sep 2019, 22:15 UTC

Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.

CVE-2019-15860 glyphandcog vulnerability CVSS: 4.3 03 Sep 2019, 07:15 UTC

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

CVE-2019-14294 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.

CVE-2019-14293 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.

CVE-2019-14292 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.

CVE-2019-14291 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.

CVE-2019-14290 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.

CVE-2019-14289 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

CVE-2019-14288 glyphandcog vulnerability CVSS: 4.3 27 Jul 2019, 19:15 UTC

An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.

CVE-2019-13291 glyphandcog vulnerability CVSS: 4.3 04 Jul 2019, 22:15 UTC

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.

CVE-2019-13289 glyphandcog vulnerability CVSS: 6.8 04 Jul 2019, 22:15 UTC

In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.

CVE-2019-13288 glyphandcog vulnerability CVSS: 4.3 04 Jul 2019, 22:15 UTC

In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

CVE-2019-13287 glyphandcog vulnerability CVSS: 4.3 04 Jul 2019, 22:15 UTC

In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to CVE-2018-16368.

CVE-2019-13286 glyphandcog vulnerability CVSS: 4.3 04 Jul 2019, 22:15 UTC

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

CVE-2019-13283 glyphandcog vulnerability CVSS: 6.8 04 Jul 2019, 20:15 UTC

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVE-2019-13282 glyphandcog vulnerability CVSS: 6.8 04 Jul 2019, 20:15 UTC

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVE-2019-13281 glyphandcog vulnerability CVSS: 6.8 04 Jul 2019, 20:15 UTC

In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified other impact.

CVE-2019-12958 glyphandcog vulnerability CVSS: 4.3 25 Jun 2019, 00:15 UTC

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc when it is trying to access the second privateDicts array element, because the privateDicts array has only one element allocated.

CVE-2019-12957 glyphandcog vulnerability CVSS: 6.8 25 Jun 2019, 00:15 UTC

In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVE-2019-12515 glyphandcog vulnerability CVSS: 5.8 02 Jun 2019, 00:29 UTC

There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.

CVE-2019-12493 glyphandcog vulnerability CVSS: 5.8 31 May 2019, 02:29 UTC

A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.

CVE-2019-12360 glyphandcog vulnerability CVSS: 5.8 27 May 2019, 23:29 UTC

A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data into dump content.

CVE-2019-9589 glyphandcog vulnerability CVSS: 6.8 06 Mar 2019, 08:29 UTC

There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-9588 glyphandcog vulnerability CVSS: 6.8 06 Mar 2019, 08:29 UTC

There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-9587 glyphandcog vulnerability CVSS: 6.8 06 Mar 2019, 08:29 UTC

There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to Catalog::countPageTree.

CVE-2011-1554 glyphandcog vulnerability CVSS: 4.3 31 Mar 2011, 23:55 UTC

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

CVE-2011-1553 glyphandcog vulnerability CVSS: 4.3 31 Mar 2011, 23:55 UTC

Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.

CVE-2011-1552 glyphandcog vulnerability CVSS: 4.3 31 Mar 2011, 23:55 UTC

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.

CVE-2011-0764 glyphandcog vulnerability CVSS: 6.8 31 Mar 2011, 22:55 UTC

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.

CVE-2010-3704 glyphandcog vulnerability CVSS: 6.8 05 Nov 2010, 18:00 UTC

The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.

CVE-2009-3609 glyphandcog vulnerability CVSS: 4.3 21 Oct 2009, 17:30 UTC

Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.

CVE-2009-3608 glyphandcog vulnerability CVSS: 9.3 21 Oct 2009, 17:30 UTC

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

CVE-2009-3606 glyphandcog vulnerability CVSS: 9.3 21 Oct 2009, 17:30 UTC

Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.

CVE-2009-3604 glyphandcog vulnerability CVSS: 9.3 21 Oct 2009, 17:30 UTC

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.

CVE-2009-3603 glyphandcog vulnerability CVSS: 9.3 21 Oct 2009, 17:30 UTC

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.

CVE-2009-0165 glyphandcog vulnerability CVSS: 10.0 23 Apr 2009, 19:30 UTC

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."

CVE-2009-1183 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.

CVE-2009-1182 glyphandcog vulnerability CVSS: 7.5 23 Apr 2009, 17:30 UTC

Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

CVE-2009-1181 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.

CVE-2009-1180 glyphandcog vulnerability CVSS: 6.8 23 Apr 2009, 17:30 UTC

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

CVE-2009-1179 glyphandcog vulnerability CVSS: 6.8 23 Apr 2009, 17:30 UTC

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.

CVE-2009-0800 glyphandcog vulnerability CVSS: 6.8 23 Apr 2009, 17:30 UTC

Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

CVE-2009-0799 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.

CVE-2009-0195 glyphandcog vulnerability CVSS: 6.8 23 Apr 2009, 17:30 UTC

Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.

CVE-2009-0166 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.

CVE-2009-0147 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.

CVE-2009-0146 glyphandcog vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.

CVE-2009-1144 glyphandcog vulnerability CVSS: 6.9 09 Apr 2009, 15:08 UTC

Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.