VDB

CVE-2005-3191

CVE-2005-3191 PUBLISHED CVSS 5.099999904632568 MEDIUM

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

EPSS 3.03% · 86.9th percentile

Risk Scores

CVSS v2.0
5.099999904632568
EPSS Score
3.03%
86.9th percentile

Affected Products

VendorProductVersions
n/an/an/a
xpdfxpdf0.91, 0.92, 0.93

Timeline

  • Dec 7, 2005 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 17, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Jul 15, 2023 EPSS Score

References

…and 98 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›