CVE Tools

Glyph-cog

2 CVEs tracked since 2010. Since Nov 2010, none of them reached CISA KEV.

Glyph-cog CVEs per month

Nov 2010 to Nov 2010. Point at a month, or focus the strip and use the arrow keys.
Glyph-cog CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2010-1120

Products

The products that kept showing up in Glyph-cog's monthly top three, with their CVEs summed over those months.

  1. Xpdf21 month

Latest CVEs

The 12 most recently published vulnerabilities affecting Glyph-cog.

  1. CVE-2025-2574Out-of-bounds array write in Xpdf 4.05 due to incorrect integer overflow checking2.9
  2. CVE-2024-7868Uninitialized variable in Xpdf 4.05 due to invalid JPEG header8.2
  3. CVE-2022-48545An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.5.5
  4. CVE-2022-41844An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability than CVE-2018-16369 and CVE-2019-16088.5.5
  5. CVE-2022-36561XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.5.5
  6. CVE-2022-38171Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead ...7.8
  7. CVE-2020-25725In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a ...5.0
  8. CVE-2019-10018An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.5.5
  9. CVE-2018-16369XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NO...5.5
  10. CVE-2018-7453Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.5.5
  11. CVE-2010-3702The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent at...7.5
  12. CVE-2010-3704The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows ...6.8

The record

Peak rank
#31 in Nov 2010
Busiest month shown
Nov 2010, 2 CVEs
Months with a KEV entry
0 since Nov 2010
Monthly snapshots
1 since 2010
Glyph-cog's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store