Xpdfreader is a lightweight, open-source PDF viewer and library that, despite maintaining a narrow product scope centered on the xpdf reader itself, occupies a prominent position in the vulnerability landscape due to its historical use in embedded systems and document-processing pipelines. The vendor's vulnerability exposure reflects the complexity of PDF parsing: recurring weaknesses include out-of-bounds reads and writes, NULL-pointer dereferences, divide-by-zero conditions, and uncontrolled recursion, each capable of destabilizing a parser tasked with handling untrusted and malformed document input. These memory-safety and logic flaws are characteristic of C-based parsers that process variable-length, deeply nested file structures, and they recur across versions as the attack surface expands with evolving PDF specification complexity. Defenders deploying xpdf should treat document-processing boundaries as a trust boundary and consider sandboxing or input validation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xpdfreader over time
Signals from CVEs in this vendor scope (121 CVEs).
121 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30860HIGH An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7. | Aug 24, 2021 | 7.8 | 91 | YES | NO |
CVE-2003-0434HIGH Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | Jul 24, 2003 | 7.5 | 57 | NO | YES |
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2004-1125HIGH Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows | Jan 10, 2005 | 9.3 | 31 | NO | NO |
CVE-2012-2142HIGH The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | Jan 9, 2020 | 7.8 | 26 | NO | NO |
CVE-2010-3702HIGH The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con | Nov 5, 2010 | 7.5 | 26 | NO | NO |
CVE-2005-3625HIGH Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t | Dec 31, 2005 | 10.0 | 26 | NO | NO |
CVE-2021-36493HIGH Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. | Feb 3, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-38928HIGH XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | Sep 21, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (121 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xpdfreader.
Media articles that mention a CVE ID that affects a product developed by Xpdfreader — matched by CVE ID, not by vendor name.