HomeFoolabsCVE-2009-3604

CVE-2009-3604

UNKNOWN
9.3CVSS
Published: 2009-10-21
Updated: 2025-04-09
AI Analysis

Description

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-399

Metadata

Primary Vendor
FOOLABS
Published
10/21/2009
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

foolabs : xpdffoolabs : xpdffoolabs : xpdfglyphandcog : xpdfreaderglyphandcog : xpdfreaderglyphandcog : xpdfreaderglyphandcog : xpdfreaderglyphandcog : xpdfreaderglyphandcog : xpdfreaderglyphandcog : xpdfreaderpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : popplerpoppler : poppler

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2009-3604 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com