Search CVE reports


Toggle filters

11 – 20 of 61 results


CVE-2021-30470

Medium priority

Some fixes available 2 of 9

A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Fixed Fixed Not affected Not affected
Show less packages

CVE-2021-30469

Medium priority
Needs evaluation

A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-20093

Medium priority
Needs evaluation

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-10723

Medium priority

Some fixes available 4 of 14

An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9687

Medium priority
Needs evaluation

PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2018-20797

Medium priority

Some fixes available 4 of 14

An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9199

Medium priority
Needs evaluation

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2018-20751

Medium priority
Needs evaluation

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2018-19532

Medium priority
Vulnerable

A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-14320

Medium priority
Needs evaluation

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open...

1 affected package

libpodofo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libpodofo Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages