CVE-2004-1125 describes a critical buffer overflow vulnerability in the Gfx::doImage function within xpdf 3.00 and other products sharing its codebase, including tetex-bin and KDE versions 3.2.x to 3.2.3 and 3.3.x to 3.3.2. This flaw allows remote attackers to trigger a denial of service (application crash) and potentially execute arbitrary code by crafting a malicious PDF file that exceeds maskColors array boundaries. The vulnerability carries a CVSS score of 9.3, indicating high severity, with a network attack vector and medium attack complexity, leading to complete confidentiality, integrity, and availability impacts. Its FAUCET Risk Score is 94/100. While there is no evidence of active exploitation (not in KEV or Hot List) and no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 11 mentions, placing it in the top 1% of CVEs for discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.20CPE matchmatch criteria | cpe:2.3:a:easy_software_products:cups:1.1.20:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:xpdf:xpdf:3.0:*:*:*:*:*:*:* | ||
3.2.3CPE matchmatch criteria | cpe:2.3:o:kde:kde:3.2.3:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:o:kde:kde:3.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.