NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67806 | CVE-2005-2097 | xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information. | 2 | 2.1 | Low | 2017-01-03 | 2011-03-07 | View | |
76969 | CVE-2000-0728 | xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack. | 2 | 7.2 | High | 2017-01-05 | 2016-10-17 | View | |
76968 | CVE-2000-0727 | xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL"s, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters. | 2 | 7.6 | High | 2017-01-05 | 2016-10-17 | View | |
69264 | CVE-2005-3626 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
69263 | CVE-2005-3625 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 17606 of 17672, showing 5 records out of 88360 total, starting on record 88026, ending on 88030