Document Filters 11.4.14.3263
Status
| Name | Version | Issue | State |
|---|---|---|---|
| bzip2 | 1.0.6 | CVE-2026-42250 |
needs_triage
|
| CVE-2023-22895 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2019-12900 |
needs_triage
|
||
| CVE-2016-3189 |
needs_triage
(vulnerability is in tool that we do not compile)
|
||
| CVE-2011-4089 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2010-0405 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2008-1372 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2005-1260 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2005-0953 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2002-0761 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2002-0760 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| CVE-2002-0759 |
not_affected
(1.0.6 does not match CVE configuration.)
|
||
| cld2 |
|
||
| flashsdk |
|
||
| freetype2 | 2.6.5 |
|
|
| giflib | 5.1.4 | CVE-2026-26740 |
not_affected
(5.1.4 does not match CVE configuration.)
|
| CVE-2026-23868 |
needs_triage
|
||
| CVE-2025-31344 |
needs_triage
|
||
| CVE-2024-45993 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2023-48161 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2023-39742 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2022-28506 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2021-40633 |
needs_triage
|
||
| CVE-2020-23922 |
needs_triage
|
||
| CVE-2019-15133 |
needs_triage
|
||
| CVE-2018-11490 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2018-11489 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2016-3977 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2016-3177 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| CVE-2015-7555 |
not_affected
(5.1.4 does not match CVE configuration.)
|
||
| international_components_for_unicode | 58.1 | CVE-2025-5222 |
needs_triage
|
| CVE-2020-21913 |
needs_triage
|
||
| CVE-2020-10531 |
needs_triage
|
||
| CVE-2018-18928 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2017-17484 |
needs_triage
|
||
| CVE-2017-15422 |
needs_triage
|
||
| CVE-2017-15396 |
needs_triage
|
||
| CVE-2017-14952 |
resolved
(patched)
|
||
| CVE-2017-7868 |
resolved
(patched)
|
||
| CVE-2017-7867 |
resolved
(patched)
|
||
| CVE-2016-7415 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2016-6293 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2015-5922 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-9911 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-9654 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-8147 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-8146 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7940 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7926 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7923 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2011-4599 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2007-4771 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2007-4770 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| libjpeg | 9b | CVE-2026-75466 |
needs_triage
|
| CVE-2026-24797 |
needs_triage
|
||
| CVE-2026-13708 |
needs_triage
|
||
| CVE-2023-37837 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2023-37836 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-37770 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-37769 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-37768 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-35166 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-32978 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-32202 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-32201 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-31796 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2022-31620 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39520 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39519 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39518 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39517 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39516 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39515 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2021-39514 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2020-14153 |
needs_triage
|
||
| CVE-2020-14152 |
needs_triage
|
||
| CVE-2018-11813 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2018-11214 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2018-11213 |
not_affected
(9b does not match CVE configuration.)
|
||
| CVE-2018-11212 |
not_affected
(9b does not match CVE configuration.)
|
||
| leptonica | 1.71 | CVE-2022-38266 |
needs_triage
|
| CVE-2020-36280 |
needs_triage
|
||
| CVE-2018-7442 |
needs_triage
|
||
| CVE-2018-7441 |
needs_triage
|
||
| CVE-2018-7440 |
needs_triage
|
||
| CVE-2018-7247 |
needs_triage
|
||
| CVE-2018-7186 |
needs_triage
|
||
| CVE-2018-3836 |
not_affected
(1.71 does not match CVE configuration.)
|
||
| CVE-2017-18196 |
not_affected
(1.71 does not match CVE configuration.)
|
||
| libpng | 1.6.28 | CVE-2026-64612 |
not_affected
(The defect is in libcupsfilters'/cups-filters' own PNG-reading caller code (_cfImageReadPNG / _cupsImageReadPNG in cupsfilters/image-png.c), not in libpng itself; libpng behaves correctly, but the CUPS filter never installs an error handler or setjmp recovery frame around png_create_read_struct(). Document Filters does not vendor, build, or link libcupsfilters or cups-filters (no external/ entry, no CMake reference, no CUPS print-filter integration anywhere in the codebase), so this caller-side defect is never exercised. Document Filters' own libpng call sites (filters/isysgraphics/source/ISYSimage.cpp) correctly install a custom error callback and setjmp(png_jmpbuf(...)) recovery around png_create_read_struct, so even the underlying unsafe pattern is not repeated here.)
|
| CVE-2026-40930 |
not_affected
(The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser's inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.)
|
||
| CVE-2026-34757 |
needs_triage
|
||
| CVE-2026-33636 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2026-33416 |
needs_triage
|
||
| CVE-2026-25646 |
needs_triage
|
||
| CVE-2026-22801 |
needs_triage
|
||
| CVE-2026-22695 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2026-3713 |
not_affected
(The vulnerability is in the contrib/pngminus/pnm2png CLI tool (contrib/pngminus/pnm2png.c), which is a standalone conversion utility shipped with the libpng source distribution. Document Filters builds libpng as an OBJECT library using only the core library source files and does not compile any contrib/ tools. The pnm2png binary is never built, linked, or invoked.)
|
||
| CVE-2025-66293 |
needs_triage
|
||
| CVE-2025-65018 |
needs_triage
|
||
| CVE-2025-64720 |
needs_triage
|
||
| CVE-2025-64506 |
needs_triage
|
||
| CVE-2025-64505 |
needs_triage
|
||
| CVE-2025-28164 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2025-28162 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2021-4214 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2019-7317 |
needs_triage
|
||
| CVE-2019-6129 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2018-14550 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2018-14048 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2018-13785 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2017-12652 |
needs_triage
|
||
| CVE-2016-10087 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2016-3751 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2015-8540 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2015-8472 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2015-8126 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2015-7981 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2015-0973 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2014-9495 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2014-0333 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2013-7354 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2013-7353 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2013-6954 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2012-3425 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-3464 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-3328 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-3048 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-3045 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-2692 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-2691 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-2690 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-2501 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2011-0408 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2010-2249 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2010-1205 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2010-0205 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2009-5063 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2009-2042 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2009-0040 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2008-6218 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2008-5907 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2008-3964 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2008-1382 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2007-5269 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2007-5268 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2007-5267 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2007-5266 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2006-7244 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2006-5793 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2006-3334 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2006-0481 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2004-0599 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2004-0598 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2004-0597 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2004-0421 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2002-1363 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2002-0728 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| CVE-2002-0660 |
not_affected
(1.6.28 does not match CVE configuration.)
|
||
| libtiff | 4.0.8 | CVE-2026-70651 |
needs_triage
|
| CVE-2026-52492 |
needs_triage
|
||
| CVE-2026-52491 |
needs_triage
|
||
| CVE-2026-52490 |
needs_triage
|
||
| CVE-2026-12912 |
not_affected
(The overflow in PixarLogDecode (tif_pixarlog.c) is only reachable when the application explicitly selects the PIXARLOGDATAFMT_8BITABGR output format by calling TIFFSetField(tif, TIFFTAG_PIXARLOGDATAFMT, PIXARLOGDATAFMT_8BITABGR). Document Filters never sets TIFFTAG_PIXARLOGDATAFMT anywhere in its codebase; its TIFF decoder (filters/isysgraphics/source/ISYStiff_decoder.cpp) reads pixels only via TIFFReadScanline and TIFFReadRGBAImageOriented. libtiff's default format selection (PixarLogGuessDataFmt) never returns PIXARLOGDATAFMT_8BITABGR, and per the upstream advisory TIFFRGBAImageBegin/TIFFReadRGBAImage do not select this format either. The vulnerable code path is therefore never exercised.)
|
||
| CVE-2026-4775 |
needs_triage
|
||
| CVE-2025-61145 |
not_affected
(The double-free vulnerability is in the tiffcrop CLI tool (tools/tiffcrop.c:2931), triggered in main() when freeing buffers after a failed image inversion. Document Filters does not compile or ship tiffcrop; only the libtiff library sources are included. The vulnerable tool code is not present in the build.)
|
||
| CVE-2025-61144 |
not_affected
(The vulnerability is entirely in the tiffcrop CLI tool (tools/tiffcrop.c) in functions readSeparateStripsIntoBuffer and combineSeparateSamplesBytes. Document Filters does not compile or ship tiffcrop; only the libtiff library sources are included. The function readSeparateStripsIntoBuffer is not present in the Document Filters build.)
|
||
| CVE-2025-61143 |
not_affected
(The vulnerability is in the tiffcrop CLI tool (tools/tiffcrop.c:2954) which passes a NULL TIFF* to TIFFFileName(). Document Filters does not compile or ship the tiffcrop CLI utility; only the libtiff library sources are included. The vulnerable tool code is not present in the build.)
|
||
| CVE-2025-9900 |
needs_triage
|
||
| CVE-2025-9165 |
not_affected
(The vulnerable code is in tools/tiffcmp.c which is not compiled into Document Filters.)
|
||
| CVE-2025-8961 |
not_affected
(Document Filters vendors libtiff 4.6.0 and does not compile or ship the tiffcrop CLI utility (tools/tiffcrop.c not part of build; no tiffcrop objects found in build output). CVE only impacts tiffcrop in 4.7.0 per NVD/VulDB advisory; our version predates affected release and excludes the tool, making the vulnerable code unreachable.)
|
||
| CVE-2025-8851 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2025-8534 |
not_affected
(Vulnerability is in tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2025-8177 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2025-8176 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2024-13978 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2024-7006 |
needs_triage
|
||
| CVE-2023-52356 |
needs_triage
|
||
| CVE-2023-52355 |
needs_triage
|
||
| CVE-2023-41175 |
not_affected
(Vulnerability is in tiff CLI tool raw2tiff; code is not compiled into Document Filters.)
|
||
| CVE-2023-40745 |
not_affected
(Vulnerability is in tiff CLI tool tiffcp; code is not compiled into Document Filters.)
|
||
| CVE-2023-30775 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2023-30774 |
exploitable
(A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.)
|
||
| CVE-2023-30086 |
not_affected
(Vulnerability is in tiff CLI tool tiffcp; code is not compiled into Document Filters.)
|
||
| CVE-2023-26966 |
not_affected
(The issue occurs when converting an corrupt little-endian SGILOG compressed TIFF to a big-endian SGILOG TIFF. Document Filters does not support creating new SGILOG compressed images, therefore the impacted code page is never executed.)
|
||
| CVE-2023-26965 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25435 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25434 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25433 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-3618 |
not_affected
(The issue only exists in the tiffcrop CLI tool, and is due to how it ignoring error state when calling the libtiff API. Document Filters does not have the same logic error in it's calling code to libtiff, and therefore not impacted.)
|
||
| CVE-2023-3576 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-3316 |
needs_triage
|
||
| CVE-2023-3164 |
not_affected
(Vulnerability is present in one of tiff tools files, which we do not compile.)
|
||
| CVE-2023-2908 |
needs_triage
|
||
| CVE-2023-2731 |
not_affected
(Issue was introduced post 4.3.0.)
|
||
| CVE-2023-1916 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0804 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0803 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0802 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0801 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.)
|
||
| CVE-2023-0800 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0799 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0798 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0797 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.)
|
||
| CVE-2023-0796 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0795 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-48281 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-40090 |
not_affected
(Document Filters detects and protects against circular references in the TIFF directory outside of libtiff, mitigating this issue.)
|
||
| CVE-2022-34526 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-22844 |
not_affected
(vulnerability is in tiff tools (specifically tiffset), example files which we do not compile.)
|
||
| CVE-2022-4645 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3970 |
needs_triage
|
||
| CVE-2022-3627 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3626 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3599 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3598 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3597 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3570 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2953 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2869 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2868 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2867 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2521 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2520 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2519 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2058 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2057 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2056 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-1623 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2022-1622 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2022-1355 |
not_affected
(Vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-1354 |
needs_triage
|
||
| CVE-2022-1210 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-1056 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0924 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0909 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2022-0908 |
needs_triage
|
||
| CVE-2022-0907 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0891 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0865 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2022-0562 |
needs_triage
|
||
| CVE-2022-0561 |
needs_triage
|
||
| CVE-2020-35524 |
needs_triage
|
||
| CVE-2020-35523 |
needs_triage
|
||
| CVE-2020-35522 |
needs_triage
|
||
| CVE-2020-35521 |
needs_triage
|
||
| CVE-2020-19144 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2020-19143 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2020-19131 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2020-18768 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2019-17546 |
needs_triage
|
||
| CVE-2019-14973 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2019-7663 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2019-6128 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-19210 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-18661 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-18557 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17795 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17101 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17100 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17000 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-16335 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-15209 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-12900 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-10963 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-10801 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2018-10779 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2018-10126 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-8905 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-7456 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-5784 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-5360 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2017-18013 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17973 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17942 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17095 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-16232 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-13727 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-13726 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-12944 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-11613 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-11335 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-10688 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9937 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9936 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9935 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9815 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9404 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9403 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9147 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9117 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7602 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7601 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7600 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7599 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7598 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7597 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7596 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7595 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7594 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7593 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7592 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-5563 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-5225 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10371 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10272 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10271 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10270 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10269 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10268 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10267 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10266 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10095 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10094 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10093 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10092 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9540 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9539 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9538 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9537 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9536 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9535 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9534 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9533 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9532 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9453 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2016-9448 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9297 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9273 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-8331 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-6223 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5652 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5323 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5322 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5321 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5319 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5318 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5317 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5316 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5315 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5314 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5102 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3991 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3990 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3945 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3658 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3634 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3633 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3632 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3631 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3625 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3624 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3623 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3622 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3621 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3620 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3619 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3186 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8870 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8784 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2015-8783 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2015-8782 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2015-8781 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2015-8683 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8668 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8665 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-7554 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-7313 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2015-1547 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-9655 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2014-9330 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8130 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8129 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8127 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-4244 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-4231 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-1961 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2013-1960 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2012-5581 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-4564 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-4447 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-3401 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-2113 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-2088 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2012-1173 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2011-1167 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-4665 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2631 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2630 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2597 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2596 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2595 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2483 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2482 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2481 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2443 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2233 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2067 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2010-2065 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2009-5022 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2009-2347 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2009-2285 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2008-2327 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3465 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3464 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3463 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3462 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3461 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-3460 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2656 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2193 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2120 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2026 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2025 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-2024 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2006-0405 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2005-2452 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2005-1544 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-1308 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-1307 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-1183 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-0929 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-0886 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-0804 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| CVE-2004-0803 |
not_affected
(4.0.8 does not match CVE configuration.)
|
||
| libwebp | 0.6.0 | CVE-2026-58586 |
not_affected
(This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module's bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.)
|
| CVE-2023-4863 |
needs_triage
|
||
| CVE-2023-1999 |
needs_triage
|
||
| CVE-2020-36332 |
needs_triage
|
||
| CVE-2020-36331 |
needs_triage
|
||
| CVE-2020-36330 |
needs_triage
|
||
| CVE-2020-36329 |
needs_triage
|
||
| CVE-2020-36328 |
needs_triage
|
||
| CVE-2018-25014 |
needs_triage
|
||
| CVE-2018-25013 |
needs_triage
|
||
| CVE-2018-25012 |
needs_triage
|
||
| CVE-2018-25011 |
needs_triage
|
||
| CVE-2018-25010 |
needs_triage
|
||
| CVE-2018-25009 |
needs_triage
|
||
| CVE-2016-9969 |
not_affected
(0.6.0 does not match CVE configuration.)
|
||
| CVE-2016-9085 |
not_affected
(0.6.0 does not match CVE configuration.)
|
||
| litehtml |
|
||
| lzma | 17.01 | CVE-2026-19671 |
needs_triage
|
| CVE-2026-15310 |
needs_triage
|
||
| CVE-2025-58058 |
needs_triage
|
||
| CVE-2025-31115 |
needs_triage
|
||
| protobuf | 3.0.0 | CVE-2026-67198 |
needs_triage
|
| CVE-2026-67195 |
needs_triage
|
||
| CVE-2026-55407 |
needs_triage
|
||
| CVE-2026-55406 |
needs_triage
|
||
| CVE-2026-52878 |
needs_triage
|
||
| CVE-2026-48599 |
needs_triage
|
||
| CVE-2026-40027 |
needs_triage
|
||
| CVE-2026-6409 |
needs_triage
|
||
| CVE-2026-0994 |
needs_triage
|
||
| CVE-2025-53605 |
needs_triage
|
||
| CVE-2024-24786 |
needs_triage
|
||
| CVE-2024-7254 |
needs_triage
|
||
| CVE-2024-2410 |
not_affected
(3.0.0 does not match CVE configuration.)
|
||
| CVE-2023-24535 |
not_affected
(3.0.0 does not match CVE configuration.)
|
||
| CVE-2021-22570 |
needs_triage
|
||
| CVE-2021-3121 |
false_positive
(Unknown vendors 'golang, hashicorp')
|
||
| CVE-2015-5237 |
needs_triage
|
||
| sfntly | CVE-2016-1709 |
resolved
(manually patched data/byte_array.cc)
|
|
| skia | CVE-2026-79147 |
needs_triage
|
|
| CVE-2026-79144 |
needs_triage
|
||
| CVE-2026-79112 |
needs_triage
|
||
| CVE-2026-79020 |
needs_triage
|
||
| CVE-2026-78958 |
needs_triage
|
||
| CVE-2013-6648 |
resolved
(patched)
|
||
| skia-svg |
|
||
| snappy | 1.1.3 | CVE-2026-49359 |
needs_triage
|
| CVE-2026-49358 |
needs_triage
|
||
| CVE-2026-49286 |
needs_triage
|
||
| CVE-2026-49260 |
needs_triage
|
||
| CVE-2026-46683 |
needs_triage
|
||
| CVE-2026-46643 |
needs_triage
|
||
| CVE-2026-44302 |
needs_triage
|
||
| CVE-2025-65942 |
not_affected
(This CVE affects VictoriaMetrics, a time series monitoring solution. We use Google Snappy compression library directly; VictoriaMetrics is not present in Document Filters.)
|
||
| CVE-2024-36124 |
false_positive
(Unknown vendors 'dain')
|
||
| CVE-2024-36114 |
not_affected
(The issue is related to Aircompressor, Java port of (among the others) Snappy. We use Snappy directly; Document Filters is not impacted.)
|
||
| CVE-2023-41330 |
false_positive
(Unknown vendors 'knplabs')
|
||
| CVE-2023-28115 |
false_positive
(Unknown vendors 'knplabs')
|
||
| CVE-2018-7577 |
not_affected
(1.1.3 does not match CVE configuration.)
|
||
| stackwalker | 13 |
|
|
| teigha |
|
||
| tesseract | 3.02.02 | CVE-2026-73067 |
needs_triage
|
| CVE-2026-73066 |
needs_triage
|
||
| CVE-2025-60176 |
not_affected
(Document Filter does not use the Tesseract WordPress plugin)
|
||
| CVE-2022-38266 |
not_affected
(3.02.02 does not match CVE configuration.)
|
||
| CVE-2019-25257 |
not_affected
(LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC's document management server application. The vulnerability is in LogicalDOC's configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.)
|
||
| CVE-2011-1136 |
not_affected
(3.02.02 does not match CVE configuration.)
|
||
| tinyspline |
|
||
| unrar | 5.3.9 | CVE-2026-14191 |
not_affected
(The vulnerable function RecVolumes5::ReadHeader in recvol5.cpp is compiled into the product (recvol.cpp #includes recvol5.cpp), but the recovery-volume (.rev) code path is unreachable in Document Filters. Every entry point into it -- RecVolumesTest (extract.cpp:124 and :225) and RecVolumesRestore (extract.cpp:339 and volume.cpp:90) -- is guarded by preprocessor conditions that exclude the code when RARDLL is defined ('#if !defined(SFX_MODULE) && !defined(RARDLL)' and '#ifndef RARDLL'). Document Filters builds unrar with RARDLL defined (external/CMakeLists.txt) and drives the library exclusively through the DLL API (RAROpenArchiveEx followed by RARProcessFile RAR_TEST/RAR_SKIP in filters/isysreaders/readers/ReaderRAR.cpp). It never performs a recovery, repair, or .rev test operation, so RecVolumes5::ReadHeader is never called and the out-of-bounds write cannot be triggered.)
|
| CVE-2025-60835 |
not_affected
(This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable 'unrar.dll' referenced in the advisory is IZArc's own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.)
|
||
| CVE-2022-48579 |
not_affected
(The problem arises within the unrar library when employing its API to unpack the archive's contents into a designated directory. Document Filters does not make use of these functions while handling rar files, and as a result, is not affected by this problem.)
|
||
| CVE-2017-14122 |
not_affected
(5.3.9 does not match CVE configuration.)
|
||
| CVE-2017-14121 |
not_affected
(5.3.9 does not match CVE configuration.)
|
||
| CVE-2017-14120 |
not_affected
(5.3.9 does not match CVE configuration.)
|
||
| CVE-2017-12942 |
needs_triage
|
||
| CVE-2017-12941 |
needs_triage
|
||
| CVE-2017-12940 |
needs_triage
|
||
| CVE-2017-12938 |
needs_triage
|
||
| CVE-2012-6706 |
needs_triage
|
||
| CVE-2007-3726 |
not_affected
(5.3.9 does not match CVE configuration.)
|
||
| CVE-2007-0855 |
not_affected
(5.3.9 does not match CVE configuration.)
|
||
| wavpack | 5.1.0 | CVE-2026-53705 |
needs_triage
|
| CVE-2022-2476 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2021-44269 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2020-35738 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2019-1010319 |
needs_triage
|
||
| CVE-2019-1010317 |
needs_triage
|
||
| CVE-2019-1010315 |
needs_triage
|
||
| CVE-2019-11498 |
needs_triage
|
||
| CVE-2018-19841 |
needs_triage
|
||
| CVE-2018-19840 |
needs_triage
|
||
| CVE-2018-10540 |
needs_triage
|
||
| CVE-2018-10539 |
needs_triage
|
||
| CVE-2018-10538 |
needs_triage
|
||
| CVE-2018-10537 |
needs_triage
|
||
| CVE-2018-10536 |
needs_triage
|
||
| CVE-2018-7254 |
needs_triage
|
||
| CVE-2018-7253 |
not_affected
(CVE is on wavpack creation, which we do not use. (https://github.com/dbry/WavPack/issues/28))
|
||
| CVE-2018-6767 |
not_affected
(CVE is on wavpack creation, which we do not use. (https://github.com/dbry/WavPack/issues/27))
|
||
| CVE-2016-10172 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2016-10171 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2016-10170 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| CVE-2016-10169 |
not_affected
(5.1.0 does not match CVE configuration.)
|
||
| zlib | 1.2.11 | CVE-2026-77640 |
needs_triage
|
| CVE-2026-77639 |
needs_triage
|
||
| CVE-2026-74767 |
needs_triage
|
||
| CVE-2026-70631 |
not_affected
(The vulnerable code is FFmpeg's own TIFF decoder (tiff_unpack_zlib() in libavcodec/tiff.c), which ignores the actual uncompress() output length and memcpy()s all declared rows out of a partially-initialized heap buffer -- the defect is in FFmpeg's application-level handling of zlib's result, not in zlib itself. Document Filters does not vendor, build, or link FFmpeg/libavcodec/libavformat in any form; no FFmpeg, tiff_unpack_zlib, or libavcodec reference exists anywhere in this codebase, so the vulnerable code is never compiled in. Document Filters decodes Deflate-compressed TIFF strips through libtiff 4.6.0 (external/libtiff-4.6.0/tif_zip.c, used by filters/isysgraphics/source/ISYStiff_decoder.cpp), whose ZIPDecode() already performs the equivalent check the FFmpeg fix adds: after the inflate loop it verifies the full expected output count was produced and, if bytes remain, raises 'Not enough data at scanline %lu (short %PRIu64 bytes)' and returns failure rather than emitting the uninitialized tail of the buffer.)
|
||
| CVE-2026-70630 |
not_affected
(The vulnerable code is FFmpeg's own Screenpresso SPV1 video decoder (screenpresso_decode_frame() in libavcodec/screenpresso.c), which ignores the actual output length returned by zlib's uncompress() and hands the full frame geometry to av_image_copy_plane() out of a partially-initialized persistent heap buffer -- the defect is in FFmpeg's application-level handling of zlib's result, not in zlib itself, and the upstream fix touches only libavcodec/screenpresso.c with no change to any zlib source file. Document Filters does not vendor, build, or link FFmpeg/libavcodec/libavformat in any form and implements no video codec of any kind; no FFmpeg, screenpresso, SPV1, inflated_buf, or av_image_copy_plane reference exists anywhere in this codebase, so the vulnerable code is never compiled in. Document Filters does identify and read AVI containers (ISYS_NS::ID::avi_video, filters/isysreaders/readers/ReaderAVI.cpp), but CAVIReader::LoadDocument() is a metadata-only RIFF header parser: it walks the 'hdrl'/'strl' header lists to emit stream, frame-rate, resolution, and audio-format metadata, then returns without reading the 'movi' chunk at all ('Ignore the rest of the file, including any idxl'). It never inspects a stream's fccHandler to dispatch a codec, never allocates a frame buffer, and never invokes zlib on packet payloads, so a crafted SPV1 packet carrying a short deflate stream is never decompressed or copied by Document Filters.)
|
||
| CVE-2026-66913 |
not_affected
(The vulnerable code is Lookyloo's own capture-archive/HAR import handling (a standalone Python web application by CIRCL), not zlib itself. Document Filters does not vendor, build, or run any Lookyloo code and has no capture-archive or HAR-import feature; the CVE's application-level defect is never exercised regardless of how Document Filters' own zlib-based ZIP/gzip decompression (shared/core/source/ISYSzlib.cpp, ISYSzipfile.cpp, filters/isysreaders/readers/ReaderGz.cpp) behaves.)
|
||
| CVE-2026-63825 |
not_affected
(CVE-2026-63825 is a Linux kernel vulnerability, not a userspace zlib vulnerability. The 'zlib_inflate' referenced in the advisory is the Linux kernel's own internal, independently-maintained decompressor (lib/zlib_inflate/ in the kernel source tree), a different codebase from the userspace madler/zlib 1.3 that Document Filters vendors -- the two share no source. The root cause requires a kernel built with GCOV coverage instrumentation (CONFIG_GCOV_KERNEL) plus the IPComp/IPsec network-compression subsystem processing attacker-controlled traffic on a multi-CPU system. Document Filters is a userspace C++ SDK with .NET/Python/Java bindings; it does not build, ship, or modify a Linux kernel, does not enable kernel GCOV instrumentation, and does not implement or use IPsec/IPComp in any form. No kernel module, GCOV kernel-build configuration, or IPComp/xfrm code exists anywhere in this codebase.)
|
||
| CVE-2026-62292 |
needs_triage
|
||
| CVE-2026-58107 |
needs_triage
|
||
| CVE-2026-58045 |
not_affected
(CVE-2026-58045 is a defect in the Node.js runtime's own zlib binding layer, not in the zlib library. The upstream fix (nodejs/node commit 0d072480c3dbbad6db8723e39786321646989343) changes only src/node_zlib.cc, replacing two CHECK(Buffer::IsWithinBounds(...)) assertions in CompressionStream::Write with THROW_ERR_OUT_OF_RANGE so a JavaScript object with a spoofed byteLength getter raises a RangeError instead of aborting the process; no zlib source file is touched. That the affected surface includes zlib.brotliCompressSync, zlib.brotliDecompressSync, zlib.zstdCompressSync, and zlib.zstdDecompressSync -- codecs zlib does not implement -- further confirms the defect lives in Node's shared binding wrapper rather than in zlib. Document Filters is a C++ SDK with .NET/Python/Java bindings; it embeds no Node.js runtime, no V8, and no N-API/NAN addon, so the vulnerable CompressionStream::Write code and the V8 TypedArray spoofing primitive it depends on are not present in the tree at all (no node_zlib.cc, no Buffer::IsWithinBounds, no THROW_ERR_OUT_OF_RANGE). Document Filters calls zlib's C API directly from shared/core/source/ISYScompressedstream.cpp and ISYSzipfile.cpp with buffer offsets and lengths it computes itself in native code, where no spoofable byteLength accessor exists. The only package.json in the repository (filters/tools/isys_readergen) is an internal build-time code generator depending solely on @types/node and commander; it is not shipped, does not use node:zlib, and no Node.js runtime is redistributed with the product.)
|
||
| CVE-2026-53430 |
needs_triage
|
||
| CVE-2026-44254 |
needs_triage
|
||
| CVE-2026-43970 |
false_positive
(CVE-2026-43970 is a vulnerability in cowlib (ninenines/cowlib), an Erlang HTTP support library, not in the zlib C library. The flaw is in cow_spdy.erl, which calls Erlang's zlib:inflate/2 against attacker-controlled SPDY-compressed headers without any output-size limit. The upstream fix (commit 16aad3fb9f81f5cda4d1706ff0c54237c619c282) deletes the entire cow_spdy module and contains no C code changes. The 'zlib' association exists only because cow_spdy used Erlang's zlib NIF for SPDY header decompression. Document Filters does not use Erlang/OTP, cowlib, cowboy, or any SPDY protocol implementation, and does not perform unbounded decompression of attacker-controlled streams.)
|
||
| CVE-2026-39804 |
false_positive
(CVE-2026-39804 is a vulnerability in Bandit (mtrudel/bandit), an Elixir HTTP server, not in the zlib C library. The flaw is unbounded decompression in Bandit's WebSocket permessage-deflate handler (Elixir.Bandit.WebSocket.PerMessageDeflate:inflate/2), which calls Erlang's :zlib.inflate/2 without output-size limits. The 'zlib' association exists only because Bandit uses Erlang's zlib NIF internally, but the vulnerability is entirely in Bandit's application-level code. Document Filters does not use Elixir, Erlang/OTP, Bandit, or any WebSocket server. Document Filters uses the C zlib library version 1.3 directly from madler/zlib for compression/decompression with proper bounded buffers.)
|
||
| CVE-2026-35469 |
false_positive
(CVE-2026-35469 is a vulnerability in moby/spdystream (a Go library for SPDY protocol multiplexing), not in the zlib C library. The flaw is unbounded memory allocation in spdystream's Go SPDY/3 frame parser (parseHeaderValueBlock). The 'zlib' association exists only because SPDY headers are zlib-compressed, but the vulnerability is entirely in the Go application code that fails to validate decompressed sizes before allocation. Document Filters does not use Go, does not include spdystream, and does not implement any SPDY protocol handling.)
|
||
| CVE-2026-29035 |
needs_triage
|
||
| CVE-2026-27820 |
not_affected
(CVE-2026-27820 affects the Ruby zlib gem (ruby/zlib), a Ruby-language binding for zlib, not the upstream C zlib library (madler/zlib). The vulnerable function zstream_buffer_ungets is Ruby-specific code that manages Ruby string buffers for Zlib::GzipReader. Document Filters uses the C zlib library version 1.3 directly from madler/zlib and does not include or use any Ruby code, the Ruby zlib gem, or the zstream_buffer_ungets function.)
|
||
| CVE-2026-27171 |
not_affected
(Document Filters never calls crc32_combine64, crc32_combine_gen64, crc32_combine, or crc32_combine_gen. The vulnerable x2nmodp infinite loop can only be triggered by passing a negative length to these combine functions — a code path that Document Filters does not exercise.)
|
||
| CVE-2026-24812 |
needs_triage
|
||
| CVE-2026-24800 |
false_positive
(CVE-2026-24800 affects the furnace project's bundled copy of zlib, not the standalone zlib library. Document Filters does not use furnace; it uses zlib 1.3 directly. The underlying vulnerability (CVE-2022-37434) was a heap buffer overflow in inflate.c when processing gzip headers with large extra fields via inflateGetHeader(). This was fixed in upstream zlib 1.2.13 via commit eff308af425b67093bab25f80f1ae950166bece1. Document Filters uses zlib 1.3 (released August 2023), which includes this fix.)
|
||
| CVE-2026-24799 |
false_positive
(CVE-2026-24799 affects the dlib library's bundled copy of zlib, not the standalone zlib library. Document Filters does not use dlib; it uses zlib 1.3 directly. The underlying vulnerability (CVE-2022-37434) was fixed in upstream zlib via commit eff308af425b67093bab25f80f1ae950166bece1, and zlib 1.3 includes this fix. Our inflate.c contains the patched code with proper bounds checking for gzip header extra fields.)
|
||
| CVE-2026-22184 |
not_affected
(Document Filters only builds zlib core sources and contrib/infback9; the vulnerable contrib/untgz utility is absent from our source tree and never shipped.)
|
||
| CVE-2026-4738 |
not_affected
(CVE-2026-4738 targets unsafe pointer arithmetic (base -= 257; extra -= 257) in inflate_table9() in contrib/infback9/inftree9.c. This is the same vulnerability already fixed in Document Filters via commit 9d560cb1803c4d8e6525a36c994c7af8b4580cff (CVE-2026-24812 fix), which backported upstream zlib commit 6a043145ca6e9c55184013841a67b2fef87e44c0. Our inftree9.c uses the safe 'match' variable pattern and does not contain the vulnerable pointer arithmetic.)
|
||
| CVE-2025-52937 |
not_affected
(The issue is specific to the PointCloudLibrary, which uses a modified version of the ZLib library. This issue does not affect Document Filters.)
|
||
| CVE-2025-5087 |
false_positive
(The issue is specific to the Kaleris NAVIS systems and is a result of improper usage of zlib library, not a vulnerability of the library itself.)
|
||
| CVE-2025-4640 |
not_affected
(Affected code is not utilized by Document Filters.)
|
||
| CVE-2023-53742 |
not_affected
(The issue is related to the Linux kernel and is not a vulnerability of the zlib library itself.)
|
||
| CVE-2023-45853 |
not_affected
(not-exploitable: CVE exists in CLI tool that is not part of zlib library.)
|
||
| CVE-2023-6992 |
false_positive
(Unknown vendors 'cloudflare')
|
||
| CVE-2022-37434 |
needs_triage
|
||
| CVE-2018-25032 |
needs_triage
|
||
| CVE-2016-9843 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2016-9842 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2016-9841 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2016-9840 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2005-2096 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2005-1849 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2004-0797 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2003-0107 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| CVE-2002-0059 |
not_affected
(1.2.11 does not match CVE configuration.)
|
||
| qpdf | 8.0.0 | CVE-2024-24246 |
not_affected
(8.0.0 does not match CVE configuration.)
|
| CVE-2022-34503 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2021-36978 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2021-25786 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2018-18020 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2018-9918 |
needs_triage
|
||
| CVE-2017-18186 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-18185 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-18184 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-18183 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-12595 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-11627 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-11626 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-11625 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-11624 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-9210 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-9209 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2017-9208 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| CVE-2015-9252 |
not_affected
(8.0.0 does not match CVE configuration.)
|
||
| openjpeg | 2.3.0 | CVE-2026-6192 |
needs_triage
|
| CVE-2025-54874 |
needs_triage
|
||
| CVE-2025-50952 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2024-56827 |
needs_triage
|
||
| CVE-2024-56826 |
needs_triage
|
||
| CVE-2023-39329 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2023-39328 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2023-39327 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2022-1122 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2021-29338 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2021-3575 |
needs_triage
|
||
| CVE-2020-27845 |
needs_triage
|
||
| CVE-2020-27844 |
needs_triage
|
||
| CVE-2020-27843 |
needs_triage
|
||
| CVE-2020-27842 |
needs_triage
|
||
| CVE-2020-27841 |
needs_triage
|
||
| CVE-2020-27824 |
needs_triage
|
||
| CVE-2020-27823 |
needs_triage
|
||
| CVE-2020-27814 |
needs_triage
|
||
| CVE-2020-15389 |
needs_triage
|
||
| CVE-2020-8112 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2020-6851 |
needs_triage
|
||
| CVE-2019-12973 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2019-6988 |
needs_triage
|
||
| CVE-2018-21010 |
needs_triage
|
||
| CVE-2018-20847 |
needs_triage
|
||
| CVE-2018-20846 |
needs_triage
|
||
| CVE-2018-20845 |
needs_triage
|
||
| CVE-2018-18088 |
needs_triage
|
||
| CVE-2018-16376 |
needs_triage
|
||
| CVE-2018-16375 |
needs_triage
|
||
| CVE-2018-14423 |
needs_triage
|
||
| CVE-2018-7648 |
needs_triage
|
||
| CVE-2018-6616 |
needs_triage
(CVE is on JPEG2000 creation, which we do not exercise (https://github.com/uclouvain/openjpeg/issues/1059))
|
||
| CVE-2018-5785 |
needs_triage
|
||
| CVE-2018-5727 |
needs_triage
(CVE is on JPEG2000 creation, which we do not exercise (https://github.com/uclouvain/openjpeg/issues/1053))
|
||
| CVE-2017-17480 |
needs_triage
|
||
| CVE-2017-17479 |
needs_triage
|
||
| CVE-2017-14164 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-14152 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-14151 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-14041 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-14040 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-14039 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2017-12982 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-10507 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-10506 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-10505 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-10504 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9675 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9581 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9580 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9573 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9572 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9118 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9117 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9116 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9115 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9114 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9113 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-9112 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-8332 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-7445 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-7163 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-4797 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-4796 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-3183 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-3182 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-1924 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2016-1923 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2015-8871 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2015-1239 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2014-0158 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-6887 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-6054 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-6053 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-6052 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-6045 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-4290 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-4289 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2013-1447 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2012-3535 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2012-3358 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2012-1499 |
not_affected
(2.3.0 does not match CVE configuration.)
|
||
| CVE-2009-5030 |
not_affected
(2.3.0 does not match CVE configuration.)
|