Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-15569

Опубликовано: 10 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6
CVSS3: 7

Описание

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.

РелизСтатусПримечание
devel

ignored

affects only Windows
esm-apps-legacy/xenial

ignored

affects only Windows
esm-apps/bionic

ignored

affects only Windows
esm-apps/focal

ignored

affects only Windows
esm-apps/jammy

ignored

affects only Windows
esm-apps/noble

ignored

affects only Windows
esm-apps/xenial

ignored

end of ESM support, was ignored [affects only Windows]
jammy

ignored

affects only Windows
noble

ignored

affects only Windows
questing

ignored

end of life, was ignored [affects only Windows]

Показывать по

EPSS

Процентиль: 2%
0.00115
Низкий

6 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
nvd
7 месяцев назад

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.

CVSS3: 7
debian
7 месяцев назад

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The im ...

CVSS3: 7
github
7 месяцев назад

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.

EPSS

Процентиль: 2%
0.00115
Низкий

6 Medium

CVSS2

7 High

CVSS3