xpdfreader CVE Vulnerabilities & Metrics

Focus on xpdfreader vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About xpdfreader Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with xpdfreader. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total xpdfreader CVEs: 80
Earliest CVE date: 30 Jul 2007, 23:17 UTC
Latest CVE date: 15 Aug 2024, 21:15 UTC

Latest CVE reference: CVE-2024-7868

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 10

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 42.86%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 42.86%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical xpdfreader CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.11

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 30
4.0-6.9 51
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS xpdfreader CVEs

These are the five CVEs with the highest CVSS scores for xpdfreader, sorted by severity first and recency.

All CVEs for xpdfreader

CVE-2024-7868 xpdfreader vulnerability CVSS: 0 15 Aug 2024, 21:15 UTC

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.

CVE-2024-7867 xpdfreader vulnerability CVSS: 0 15 Aug 2024, 20:15 UTC

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

CVE-2024-7866 xpdfreader vulnerability CVSS: 0 15 Aug 2024, 20:15 UTC

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

CVE-2024-4976 xpdfreader vulnerability CVSS: 0 15 May 2024, 21:15 UTC

Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.

CVE-2024-4568 xpdfreader vulnerability CVSS: 0 06 May 2024, 20:15 UTC

In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.

CVE-2024-4141 xpdfreader vulnerability CVSS: 0 24 Apr 2024, 19:15 UTC

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

CVE-2024-3900 xpdfreader vulnerability CVSS: 0 17 Apr 2024, 19:15 UTC

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.

CVE-2024-3248 xpdfreader vulnerability CVSS: 0 02 Apr 2024, 23:15 UTC

In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

CVE-2024-3247 xpdfreader vulnerability CVSS: 0 02 Apr 2024, 23:15 UTC

In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.

CVE-2024-2971 xpdfreader vulnerability CVSS: 0 26 Mar 2024, 22:15 UTC

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.

CVE-2022-48545 xpdfreader vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.

CVE-2023-3436 xpdfreader vulnerability CVSS: 0 27 Jun 2023, 21:15 UTC

Xpdf 4.04 will deadlock on a PDF object stream whose "Length" field is itself in another object stream.

CVE-2023-3044 xpdfreader vulnerability CVSS: 0 02 Jun 2023, 23:15 UTC

An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate.

CVE-2023-2664 xpdfreader vulnerability CVSS: 0 11 May 2023, 21:15 UTC

 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.

CVE-2023-2663 xpdfreader vulnerability CVSS: 0 11 May 2023, 21:15 UTC

 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.

CVE-2023-2662 xpdfreader vulnerability CVSS: 0 11 May 2023, 21:15 UTC

In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.

CVE-2023-26930 xpdfreader vulnerability CVSS: 0 26 Apr 2023, 19:15 UTC

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”

CVE-2022-45587 xpdfreader vulnerability CVSS: 0 15 Feb 2023, 18:15 UTC

Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVE-2022-45586 xpdfreader vulnerability CVSS: 0 15 Feb 2023, 18:15 UTC

Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVE-2021-36493 xpdfreader vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

CVE-2022-43071 xpdfreader vulnerability CVSS: 0 15 Nov 2022, 17:15 UTC

A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

CVE-2022-43295 xpdfreader vulnerability CVSS: 0 14 Nov 2022, 21:15 UTC

XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.

CVE-2022-41844 xpdfreader vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.

CVE-2022-41843 xpdfreader vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.

CVE-2022-41842 xpdfreader vulnerability CVSS: 0 30 Sep 2022, 05:15 UTC

An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.

CVE-2022-38222 xpdfreader vulnerability CVSS: 0 29 Sep 2022, 03:15 UTC

There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVE-2022-38928 xpdfreader vulnerability CVSS: 0 21 Sep 2022, 13:15 UTC

XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

CVE-2022-38334 xpdfreader vulnerability CVSS: 0 15 Sep 2022, 21:15 UTC

XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.

CVE-2022-36561 xpdfreader vulnerability CVSS: 0 30 Aug 2022, 21:15 UTC

XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.

CVE-2022-38171 xpdfreader vulnerability CVSS: 0 22 Aug 2022, 19:15 UTC

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

CVE-2022-33108 xpdfreader vulnerability CVSS: 6.8 28 Jun 2022, 17:15 UTC

XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.

CVE-2021-27548 xpdfreader vulnerability CVSS: 4.3 18 May 2022, 15:15 UTC

There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.

CVE-2022-30775 xpdfreader vulnerability CVSS: 4.3 16 May 2022, 03:15 UTC

xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.

CVE-2022-30524 xpdfreader vulnerability CVSS: 6.8 09 May 2022, 18:15 UTC

There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2022-27135 xpdfreader vulnerability CVSS: 4.3 25 Apr 2022, 13:15 UTC

xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

CVE-2021-30860 xpdfreader vulnerability CVSS: 6.8 24 Aug 2021, 19:15 UTC

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2020-35376 xpdfreader vulnerability CVSS: 5.0 26 Dec 2020, 04:15 UTC

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

CVE-2020-25725 xpdfreader vulnerability CVSS: 4.3 21 Nov 2020, 06:15 UTC

In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.

CVE-2020-24999 xpdfreader vulnerability CVSS: 6.8 03 Sep 2020, 23:15 UTC

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2020-24996 xpdfreader vulnerability CVSS: 6.8 03 Sep 2020, 23:15 UTC

There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2012-2142 xpdfreader vulnerability CVSS: 6.8 09 Jan 2020, 21:15 UTC

The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

CVE-2010-0207 xpdfreader vulnerability CVSS: 4.3 30 Oct 2019, 21:15 UTC

In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.

CVE-2010-0206 xpdfreader vulnerability CVSS: 4.3 30 Oct 2019, 21:15 UTC

xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

CVE-2019-10026 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.

CVE-2019-10025 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

CVE-2019-10024 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.

CVE-2019-10023 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

CVE-2019-10022 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.

CVE-2019-10021 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.

CVE-2019-10020 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.

CVE-2019-10019 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes.

CVE-2019-10018 xpdfreader vulnerability CVSS: 4.3 25 Mar 2019, 00:29 UTC

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.

CVE-2019-9878 xpdfreader vulnerability CVSS: 6.8 21 Mar 2019, 16:01 UTC

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2019-9877 xpdfreader vulnerability CVSS: 6.8 21 Mar 2019, 16:01 UTC

There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2018-18651 xpdfreader vulnerability CVSS: 4.3 25 Oct 2018, 13:29 UTC

An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by a large number after the /Count field in the file.

CVE-2018-18650 xpdfreader vulnerability CVSS: 4.3 25 Oct 2018, 13:29 UTC

An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused by the program attempting a malloc operation for a large amount of memory.

CVE-2018-18459 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-18458 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-18457 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-18456 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-18455 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-18454 xpdfreader vulnerability CVSS: 4.3 18 Oct 2018, 06:29 UTC

CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-16369 xpdfreader vulnerability CVSS: 4.3 03 Sep 2018, 00:29 UTC

XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.

CVE-2018-16368 xpdfreader vulnerability CVSS: 4.3 03 Sep 2018, 00:29 UTC

SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

CVE-2018-11033 xpdfreader vulnerability CVSS: 6.8 14 May 2018, 00:29 UTC

The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.

CVE-2018-8107 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8106 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8105 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8104 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8103 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8102 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8101 xpdfreader vulnerability CVSS: 4.3 14 Mar 2018, 03:29 UTC

The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-8100 xpdfreader vulnerability CVSS: 6.8 14 Mar 2018, 03:29 UTC

The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-7455 xpdfreader vulnerability CVSS: 4.3 24 Feb 2018, 06:29 UTC

An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-7454 xpdfreader vulnerability CVSS: 4.3 24 Feb 2018, 06:29 UTC

A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-7453 xpdfreader vulnerability CVSS: 4.3 24 Feb 2018, 06:29 UTC

Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.

CVE-2018-7452 xpdfreader vulnerability CVSS: 4.3 24 Feb 2018, 06:29 UTC

A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

CVE-2018-7175 xpdfreader vulnerability CVSS: 4.3 15 Feb 2018, 21:29 UTC

An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.

CVE-2018-7174 xpdfreader vulnerability CVSS: 4.3 15 Feb 2018, 21:29 UTC

An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.

CVE-2018-7173 xpdfreader vulnerability CVSS: 4.3 15 Feb 2018, 21:29 UTC

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVE-2010-3702 xpdfreader vulnerability CVSS: 7.5 05 Nov 2010, 18:00 UTC

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.

CVE-2007-3387 xpdfreader vulnerability CVSS: 6.8 30 Jul 2007, 23:17 UTC

Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.