
CVE-2022-24106 – Gentoo Linux Security Advisory 202405-18
https://notcve.org/view.php?id=CVE-2022-24106
30 Aug 2022 — In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc. En Xpdf versiones anteriores a 4.04, el descodificador DCT (JPEG) permitía de forma incorrecta cambiar el flag "interleaved" después del primer escaneo de la imagen, conllevando a una vulnerabilidad desconocida relacionada con los enteros en Stream.cc Multiple vulnerabilities have been discovered in Xp... • http://www.xpdfreader.com/security-fixes.html • CWE-190: Integer Overflow or Wraparound •

CVE-2022-24107 – Gentoo Linux Security Advisory 202405-18
https://notcve.org/view.php?id=CVE-2022-24107
30 Aug 2022 — Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. Xpdf versiones anteriores a 4.04, carece de una comprobación de desbordamiento de enteros en el archivo JPXStream.cc Multiple vulnerabilities have been discovered in Xpdf, the worst of which could possibly lead to arbitrary code execution. Versions greater than or equal to 4.04 are affected. • http://www.xpdfreader.com/security-fixes.html • CWE-190: Integer Overflow or Wraparound •

CVE-2019-16115
https://notcve.org/view.php?id=CVE-2019-16115
08 Sep 2019 — In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact. En Xpdf 4.01.01, podría desencadenar una lectura insuficiente del búfer basado en pila en IdentityFunction :: transform en Function.cc, utilizado por GfxAxialS... • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41872 • CWE-125: Out-of-bounds Read •

CVE-2019-14294
https://notcve.org/view.php?id=CVE-2019-14294
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read. Se detectó un problema en Xpdf versión 4.01.01. Se presenta un uso de memoria previamente liberada en la función JPXStream::fillReadBuf en el archivo JPXStream.cc, debido a una lectura fuera de límites. • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-125: Out-of-bounds Read CWE-416: Use After Free •

CVE-2019-14293
https://notcve.org/view.php?id=CVE-2019-14293
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2. Se detectó un problema en Xpdf versión 4.01.01. Se presenta una lectura fuera de límites en la función GfxPatchMeshShading::parse en el archivo GfxState.cc para el typeA! • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-125: Out-of-bounds Read •

CVE-2019-14292
https://notcve.org/view.php?id=CVE-2019-14292
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1. Se detectó un problema en Xpdf versión 4.01.01. Se presenta una lectura fuera de límites en la función GfxPatchMeshShading::parse en el archivo GfxState.cc para typeA! • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-125: Out-of-bounds Read •

CVE-2019-14291
https://notcve.org/view.php?id=CVE-2019-14291
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3. Se detectó un problema en Xpdf versión 4.01.01. Se presenta una lectura fuera de límites en la función GfxPatchMeshShading::parse en el archivo GfxState.cc para typeA==6 caso 3. • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-125: Out-of-bounds Read •

CVE-2019-14290
https://notcve.org/view.php?id=CVE-2019-14290
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2. Se detectó un problema en Xpdf versión 4.01.01. Se presenta una lectura fuera de límites en la función GfxPatchMeshShading::parse en el archivo GfxState.cc para typeA==6 caso 2. • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-125: Out-of-bounds Read •

CVE-2019-14289
https://notcve.org/view.php?id=CVE-2019-14289
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case. Se detectó un problema en Xpdf versión 4.01.01. Se presenta un desbordamiento de enteros en la función JBIG2Bitmap::combine en el archivo JBIG2Stream.cc para el caso "multiple bytes per line". • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-190: Integer Overflow or Wraparound •

CVE-2019-14288
https://notcve.org/view.php?id=CVE-2019-14288
27 Jul 2019 — An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case. Se detectó un problema en Xpdf versión 4.01.01. Se presenta un desbordamiento de enteros en la función JBIG2Bitmap::combine en el archivo JBIG2Stream.cc para el caso "one byte per line". • https://forum.xpdfreader.com/viewtopic.php?f=3&t=41851 • CWE-190: Integer Overflow or Wraparound •