Xpdf

Vendor:

First CVE: Oct 20, 2000 · Active for 25 years

121
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Xpdf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Oct 16, 2025
281 days ago

CVE Severity & Scoring

Xpdf121 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local90 (74.4%)
Network3 (2.5%)
Unknown28 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low91 (75.2%)
High2 (1.7%)
Unknown28 (23.1%)
User Interaction
None12 (9.9%)
Unknown28 (23.1%)
Required81 (66.9%)
Privileges Required
Low6 (5.0%)
High0 (0.0%)
None87 (71.9%)
Unknown28 (23.1%)

Top CVEs

Signals from CVEs in this product scope (121 CVEs).

121 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Jul 24, 20037.557NOYES
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras
Jan 27, 200510.034NONO
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra
Jan 27, 200510.033NONO
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows
Jan 10, 20059.331NONO
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
Jan 9, 20207.826NONO
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con
Nov 5, 20107.526NONO
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t
Dec 31, 200510.026NONO
Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
Feb 3, 20237.525NONO
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
Sep 21, 20227.825NONO

Exploit Exposure

Signals from CVEs in this product scope (121 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.8% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (121 CVEs).

Media Mentions

Signals from CVEs in this product scope (121 CVEs).

Top CNAs Publishing CVEs For Xpdf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.417.81.6%00
4.04156.00.4%00
4.0336.20.9%00
4.0.227.81.1%00
4.0236.21.1%00
4.01.0195.50.9%00
4.0.117.81.1%00
4.0.017.81.2%00
4.00265.71.0%00
3.0_pl345.02.7%00
3.0_pl255.33.4%00
3.04-425.51.0%00
3.04-1325.51.0%00
3.04117.00.3%00
3.03-1725.51.0%00
3.02p1119.36.4%00
3.0237.43.6%00
3.0.1_pl216.86.0%00
3.0.1_pl147.85.4%00
3.0.156.44.5%00