Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-10118

Опубликовано: 01 июн. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the tilingPatternFill function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

EPSS

Процентиль: 17%
0.00252
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
redhat
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

CVSS3: 7.8
debian
около 2 месяцев назад

A flaw was found in Poppler's Splash backend. A remote attacker could ...

rocky
около 2 месяцев назад

Important: poppler security update

rocky
около 2 месяцев назад

Important: poppler security update

EPSS

Процентиль: 17%
0.00252
Низкий

7.8 High

CVSS3

Дефекты

CWE-190
CWE-190