Xpdf
Vendor:
First CVE: Oct 20, 2000 · Active for 25 years
121
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Xpdf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Oct 16, 2025
281 days ago
CVE Severity & Scoring
Xpdf121 CVEs
60%
36%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local90 (74.4%)
Network3 (2.5%)
Unknown28 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low91 (75.2%)
High2 (1.7%)
Unknown28 (23.1%)
User Interaction
None12 (9.9%)
Unknown28 (23.1%)
Required81 (66.9%)
Privileges Required
Low6 (5.0%)
High0 (0.0%)
None87 (71.9%)
Unknown28 (23.1%)
Top CVEs
Signals from CVEs in this product scope (121 CVEs).
121 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30860HIGH An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7. | Aug 24, 2021 | 7.8 | 91 | YES | NO |
CVE-2003-0434HIGH Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | Jul 24, 2003 | 7.5 | 57 | NO | YES |
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2004-1125HIGH Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows | Jan 10, 2005 | 9.3 | 31 | NO | NO |
CVE-2012-2142HIGH The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator. | Jan 9, 2020 | 7.8 | 26 | NO | NO |
CVE-2010-3702HIGH The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con | Nov 5, 2010 | 7.5 | 26 | NO | NO |
CVE-2005-3625HIGH Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t | Dec 31, 2005 | 10.0 | 26 | NO | NO |
CVE-2021-36493HIGH Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command. | Feb 3, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-38928HIGH XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. | Sep 21, 2022 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (121 CVEs).
CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.8% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (121 CVEs).
Media Mentions
Signals from CVEs in this product scope (121 CVEs).
Top CNAs Publishing CVEs For Xpdf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.4 | 1 | 7.8 | 1.6% | 0 | 0 |
| 4.04 | 15 | 6.0 | 0.4% | 0 | 0 |
| 4.03 | 3 | 6.2 | 0.9% | 0 | 0 |
| 4.0.2 | 2 | 7.8 | 1.1% | 0 | 0 |
| 4.02 | 3 | 6.2 | 1.1% | 0 | 0 |
| 4.01.01 | 9 | 5.5 | 0.9% | 0 | 0 |
| 4.0.1 | 1 | 7.8 | 1.1% | 0 | 0 |
| 4.0.0 | 1 | 7.8 | 1.2% | 0 | 0 |
| 4.00 | 26 | 5.7 | 1.0% | 0 | 0 |
| 3.0_pl3 | 4 | 5.0 | 2.7% | 0 | 0 |
| 3.0_pl2 | 5 | 5.3 | 3.4% | 0 | 0 |
| 3.04-4 | 2 | 5.5 | 1.0% | 0 | 0 |
| 3.04-13 | 2 | 5.5 | 1.0% | 0 | 0 |
| 3.04 | 11 | 7.0 | 0.3% | 0 | 0 |
| 3.03-17 | 2 | 5.5 | 1.0% | 0 | 0 |
| 3.02p11 | 1 | 9.3 | 6.4% | 0 | 0 |
| 3.02 | 3 | 7.4 | 3.6% | 0 | 0 |
| 3.0.1_pl2 | 1 | 6.8 | 6.0% | 0 | 0 |
| 3.0.1_pl1 | 4 | 7.8 | 5.4% | 0 | 0 |
| 3.0.1 | 5 | 6.4 | 4.5% | 0 | 0 |