Xpdf Project maintains a lightweight, open-source PDF parser that has remained prominent in the vulnerability landscape despite its narrow product scope, reflecting its wide adoption in embedded and specialized applications. The vendor's vulnerability exposure recurs consistently around memory-safety and validation weaknesses—out-of-bounds writes, buffer overflows, improper exception handling, and incorrect comparisons—that are characteristic of C-based parsing code operating on untrusted document inputs. Defenders should treat Xpdf updates as relevant to any application or embedded system that bundles this parser, since remediation often depends on downstream vendors; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xpdf Project over time
Signals from CVEs in this vendor scope (121 CVEs).
121 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30860HIGH An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7. | Aug 24, 2021 | 7.8 | 91 | YES | NO |
CVE-2003-0434HIGH Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | Jul 24, 2003 | 7.5 | 57 | NO | YES |
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2004-1125HIGH Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows | Jan 10, 2005 | 9.3 | 31 | NO | NO |
CVE-2012-2142HIGH The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | Jan 9, 2020 | 7.8 | 26 | NO | NO |
CVE-2010-3702HIGH The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con | Nov 5, 2010 | 7.5 | 26 | NO | NO |
CVE-2005-3625HIGH Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t | Dec 31, 2005 | 10.0 | 26 | NO | NO |
CVE-2021-36493HIGH Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. | Feb 3, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-38928HIGH XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | Sep 21, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (121 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xpdf Project.
Media articles that mention a CVE ID that affects a product developed by Xpdf Project — matched by CVE ID, not by vendor name.