Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-26936: publicize CVE

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via gmalloc in gmem.cc

CVE
#vulnerability#dos#pdf#buffer_overflow#ibm

publicize CVE

[CVE ID]

CVE-2022-44232

[the name of an affected Product]

libming

[the affected or fixed version(s)]

libming 0.4.8

> [Affected Product Code Base]

> libming 0.4.8 - 0.4.8

[Vulnerability Type]

Buffer Overflow

> [Impact Denial of Service]

>> true

> [Attack Vectors]

> open a crafted swf file

[DESCRIPTION]

In libming 0.4.8 decompile.c, accessing zero page may lead to denial of service.

[CVE ID]

CVE-2023-26930

[PRODUCT]

XPDF

[VERSION]

XPDF 4.04

> [Affected Product Code Base]

>> XPDF 4.04

[PROBLEM TYPE]

Buffer Overflow

> [Impact Denial of Service]

>> true

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function.

[CVE ID]

CVE-2023-26931

[ the name of an affected Product]

XPDF

[VERSION]

XPDF 4.04

[Vulnerability TYPE]

Buffer Overflow

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in TextOutputDev.cc.

[CVE ID]

CVE-2023-26934

[PRODUCT]

XPDF

[VERSION]

XPDF 4.04

[Affected Product Code Base]

XPDF 4.04

[VulnerabilityType Other]

Large or infinite loop

[Impact Denial of Service]

true

[DESCRIPTION]

An issue found in XPDF v.4.04 allows an attacker to cause a denial of service via a crafed pdf file in the object.cc parameter.

[CVE ID]

CVE-2023-26935

[PRODUCT]

XPDF 4.04

[VERSION]

4.04

> [Affected Product Code Base]

>> XPDF 4.04

[PROBLEM TYPE]

Buffer Overflow

> [Impact Denial of Service]

>> true

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via SharedFile::readBlock at /xpdf/Stream.cc.

[CVE ID]

CVE-2023-26936

[PRODUCT]

XPDF

[VERSION]

XPDF 4.04

> [Affected Product Code Base]

>> XPDF 4.04 4.04

[VulnerabilityType Other]

Large or infinite loop

> [Impact Denial of Service]

>> true

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via gmalloc in gmem.cc

[CVE ID]

CVE-2023-26937

[PRODUCT]

XPDF

[VERSION]

4.04

> [Affected Product Code Base]

>> XPDF 4.04 4.04

> [VulnerabilityType Other]

>> Large or infinite loop

> [Impact Denial of Service]

>> true

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via GString::resize located in goo/GString.cc

[CVE ID]

CVE-2023-26938

[PRODUCT]

XPDF 4.04

[VERSION]

XPDF 4.04

> [Affected Product Code Base]

>> XPDF 4.04

> [VulnerabilityType Other]

>> Large or infinite loop

> [Impact Denial of Service]

>> true

[DESCRIPTION]

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service viaSharedFile::readBlock located in goo/gfile.cc.

Related news

CVE-2022-44232: GitHub - huanglei3/libming_crashes

libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.

CVE-2023-26930: GitHub - huanglei3/xpdf_aborted

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function.

CVE-2023-26931

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the TextOutputDev.cc function.

CVE-2023-26934: xpdf_Stack-backtracking/object_copy at main · huanglei3/xpdf_Stack-backtracking

An issue found in XPDF v.4.04 allows an attacker to cause a denial of service via a crafted pdf file in the object.cc parameter.

CVE-2023-26935: GitHub - huanglei3/xpdf_heapoverflow

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via SharedFile::readBlock at /xpdf/Stream.cc.

CVE-2023-26937: xpdf_Stack-backtracking/Stack_backtracking_gstring at main · huanglei3/xpdf_Stack-backtracking

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via GString::resize located in goo/GString.cc

CVE-2023-26938

Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service viaSharedFile::readBlock located in goo/gfile.cc.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907