Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3387

23
FAUCET Score

CVE-2007-3387 describes an integer overflow vulnerability in the StreamPredictor::StreamPredictor function of xpdf 3.02 and various derivative products like poppler, gpdf, and CUPS. This flaw allows remote attackers to potentially execute arbitrary code through a crafted PDF file, triggering a stack-based buffer overflow in the StreamPredictor::getNextLine function. With a CVSS score of 6.8, this vulnerability is of medium severity, requiring no authentication and moderate attack complexity, but could lead to partial compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.11CPE matchmatch criteria
cpe:2.3:a:apple:cups:*:*:*:*:*:*:*:*
< 0.5.91CPE matchmatch criteria
cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
< 2.8.2CPE matchmatch criteria
cpe:2.3:a:gpdf_project:gpdf:*:*:*:*:*:*:*:*
3.02CPE matchmatch criteria
cpe:2.3:a:xpdfreader:xpdf:3.02:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
8.57%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0857 is in the 94th percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: tetex-0:1.0.7-38.5E.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: xpdf-1:0.92-18.RHEL2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: cups-1:1.1.17-13.3.45
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: tetex-0:1.0.7-67.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: xpdf-1:2.02-10.RHEL3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: cups-1:1.1.22-0.rc1.9.20.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kdegraphics-7:3.3.1-4.RHEL4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: gpdf-0:2.8.2-7.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: tetex-0:2.0.2-22.0.1.EL4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: xpdf-1:3.00-12.RHEL4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: cups-1:1.2.4-11.5.3.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kdegraphics-7:3.5.4-2.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: tetex-0:3.0-33.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: poppler-0:0.5.4-4.1.el5
View patch

Vendor Advisories (1)

redhatCVE-2007-3387Important

xpdf integer overflow

Jul 28, 2007

References

ftp.foolabs.com / pub/xpdf/xpdf-3.02pl1.patch
Broken Link
patches.sgi.com / support/free/security/advisories/20070801-01-P.asc
Broken Link
bugs.gentoo.org / show_bug.cgi
Issue TrackingThird Party Advisory
bugzilla.redhat.com / bugzilla/show_bug.cgi
Issue TrackingThird Party Advisory
osvdb.org / 40127
Broken Link
secunia.com / advisories/26188
Third Party Advisory
secunia.com / advisories/26251
Third Party Advisory
secunia.com / advisories/26254
Third Party Advisory
secunia.com / advisories/26255
Third Party Advisory
secunia.com / advisories/26257
Third Party Advisory
secunia.com / advisories/26278
Third Party Advisory
secunia.com / advisories/26281
Third Party Advisory
secunia.com / advisories/26283
Third Party Advisory
secunia.com / advisories/26292
Third Party Advisory
secunia.com / advisories/26293
Third Party Advisory
secunia.com / advisories/26297
Third Party Advisory
secunia.com / advisories/26307
Third Party Advisory
secunia.com / advisories/26318
Third Party Advisory
secunia.com / advisories/26325
Third Party Advisory
secunia.com / advisories/26342
Third Party Advisory
secunia.com / advisories/26343
Third Party Advisory
secunia.com / advisories/26358
Third Party Advisory
secunia.com / advisories/26365
Third Party Advisory
secunia.com / advisories/26370
Third Party Advisory
secunia.com / advisories/26395
Third Party Advisory
secunia.com / advisories/26403
Third Party Advisory
secunia.com / advisories/26405
Third Party Advisory
secunia.com / advisories/26407
Third Party Advisory
secunia.com / advisories/26410
Third Party Advisory
secunia.com / advisories/26413
Third Party Advisory
secunia.com / advisories/26425
Third Party Advisory
secunia.com / advisories/26432
Third Party Advisory
secunia.com / advisories/26436
Third Party Advisory
secunia.com / advisories/26467
Third Party Advisory
secunia.com / advisories/26468
Third Party Advisory
secunia.com / advisories/26470
Third Party Advisory
secunia.com / advisories/26514
Third Party Advisory
secunia.com / advisories/26607
Third Party Advisory
secunia.com / advisories/26627
Third Party Advisory
secunia.com / advisories/26862
Third Party Advisory
secunia.com / advisories/26982
Third Party Advisory
secunia.com / advisories/27156
Third Party Advisory
secunia.com / advisories/27281
Third Party Advisory
secunia.com / advisories/27308
Third Party Advisory
secunia.com / advisories/27637
Third Party Advisory
secunia.com / advisories/30168
Third Party Advisory
security.gentoo.org / glsa/glsa-200709-12.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200709-17.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200710-20.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200711-34.xml
Third Party Advisory
security.gentoo.org / glsa/glsa-200805-13.xml
Third Party Advisory
issues.foresightlinux.org / browse/FL-471
Broken Link
issues.rpath.com / browse/RPL-1596
Broken Link
issues.rpath.com / browse/RPL-1604
Broken Link
slackware.com / security/viewer.php
Third Party Advisory
sourceforge.net / project/shownotes.php
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11149
Third Party Advisory
support.avaya.com / elmodocs2/security/ASA-2007-401.htm
Third Party Advisory
debian.org / security/2007/dsa-1347
Third Party Advisory
debian.org / security/2007/dsa-1348
Third Party Advisory
debian.org / security/2007/dsa-1349
Third Party Advisory
debian.org / security/2007/dsa-1350
Third Party Advisory
debian.org / security/2007/dsa-1352
Third Party Advisory
debian.org / security/2007/dsa-1354
Third Party Advisory
debian.org / security/2007/dsa-1355
Third Party Advisory
debian.org / security/2007/dsa-1357
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200710-08.xml
Third Party Advisory
kde.org / info/security/advisory-20070730-1.txt
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
novell.com / linux/security/advisories/2007_15_sr.html
Broken Link
novell.com / linux/security/advisories/2007_16_sr.html
Broken Link
redhat.com / support/errata/RHSA-2007-0720.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0729.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0730.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0731.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0732.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-0735.html
Third Party Advisory
securityfocus.com / archive/1/476508/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/476519/30/5400/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/476765/30/5340/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/25124
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
slackware.org / security/viewer.php
Third Party Advisory
ubuntu.com / usn/usn-496-1
Third Party Advisory
ubuntu.com / usn/usn-496-2
Third Party Advisory
vupen.com / english/advisories/2007/2704
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2007/2705
Permissions RequiredThird Party Advisory