Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-8868

Опубликовано: 06 мая 2016
Источник: nvd
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:freedesktop:poppler:0.39.0:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00802
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.

redhat
больше 9 лет назад

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.

CVSS3: 7.8
debian
больше 9 лет назад

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunc ...

suse-cvrf
больше 9 лет назад

Security update for poppler

suse-cvrf
больше 9 лет назад

Security update for poppler

EPSS

Процентиль: 73%
0.00802
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-119