Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2008-1693

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

  • Published: Apr 18, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-1693
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
poppler / poppler 0.3.2 0.3.2.x
poppler / poppler 0.4.0 0.4.0.x
poppler / poppler 0.7.1 0.7.1.x
poppler / poppler 0.6.1 0.6.1.x
poppler / poppler 0.3.1 0.3.1.x
poppler / poppler 0.5.2 0.5.2.x
poppler / poppler 0.5.91 0.5.91.x
poppler / poppler 0.6.0 0.6.0.x
poppler / poppler 0.3.3 0.3.3.x
poppler / poppler 0.4.2 0.4.2.x
poppler / poppler 0.6.4 0.6.4.x
poppler / poppler 0.1.2 0.1.2.x
poppler / poppler 0.7.0 0.7.0.x
poppler / poppler 0.7.2 0.7.2.x
poppler / poppler 0.5.0 0.5.0.x
poppler / poppler 0.5.9 0.5.9.x
poppler / poppler 0.6.3 0.6.3.x
poppler / poppler 0.2.0 0.2.0.x
poppler / poppler 0.5.4 0.5.4.x
poppler / poppler 0.1.1 0.1.1.x
poppler / poppler - 0.7.3.x
poppler / poppler 0.4.1 0.4.1.x
poppler / poppler 0.5.3 0.5.3.x
poppler / poppler 0.4.4 0.4.4.x
poppler / poppler 0.3.0 0.3.0.x
poppler / poppler 0.1 0.1.x
poppler / poppler 0.6.2 0.6.2.x
poppler / poppler 0.4.3 0.4.3.x
poppler / poppler 0.5.1 0.5.1.x