CVE-2009-1182 describes multiple buffer overflow vulnerabilities within the JBIG2 MMR decoder, impacting Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other related products from Apple, Foolabs, and Glyph & Cog. This vulnerability allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted PDF file. With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.5a:*:*:*:*:*:*:* | ||
0.7aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.7a:*:*:*:*:*:*:* | ||
0.91aCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91a:*:*:*:*:*:*:* | ||
0.91bCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91b:*:*:*:*:*:*:* | ||
0.91cCPE matchmatch criteria | cpe:2.3:a:foolabs:xpdf:0.91c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.