VDB
CVE-2005-3191
CVE-2005-3191
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.
EPSS 4.08% · 90.1th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
4.08%
90.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| xpdf | xpdf | 0.91, 0.92, 0.93 |
Timeline
- Dec 7, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 17929 third-party-advisory
- 18349 third-party-advisory
- oval:org.mitre.oval:def:9760 vdb
- 18554 third-party-advisory
- 19230 third-party-advisory
- FLSA-2006:176751 vendor-advisory
- RHSA-2005:840 vendor-advisory
- 18313 third-party-advisory
- RHSA-2005:868 vendor-advisory
- GLSA-200512-08 vendor-advisory
- 18336 third-party-advisory
- xpdf-dctstream-progressive-bo(23443) vdb
- ADV-2005-2788 vdb
- 19798 third-party-advisory
- DSA-940 vendor-advisory
- FLSA:175404 vendor-advisory
- SCOSA-2006.21 vendor-advisory
- DSA-938 vendor-advisory
- 18387 third-party-advisory
- 233 third-party-advisory
…and 98 more