VDB
CVE-2005-3627
CVE-2005-3627
PUBLISHED
CVSS 7.5 HIGH
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.
EPSS 5.52% · 92.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.52%
92.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| xpdf | xpdf |
Timeline
- Dec 31, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Apr 12, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- SCOSA-2006.15 vendor-advisory
- 18312 third-party-advisory
- 18425 third-party-advisory
- 18373 third-party-advisory
- 18554 third-party-advisory
- 102972 vendor-advisory
- RHSA-2006:0163 vendor-advisory
- SUSE-SA:2006:001 vendor-advisory
- 18329 third-party-advisory
- 20051201-01-U vendor-advisory
- 18436 third-party-advisory
- ADV-2007-2280 vdb
- 18517 third-party-advisory
- 25729 third-party-advisory
- 19377 third-party-advisory
- 18675 third-party-advisory
- 18913 third-party-advisory
- 18375 third-party-advisory
- 18644 third-party-advisory
- DSA-931 vendor-advisory
…and 69 more