Document Filters 25.3
Status
| Name | Version | Issue | State |
|---|---|---|---|
| bzip2 | 1.0.8 | CVE-2026-42250 |
needs_triage
|
| CVE-2023-22895 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2019-12900 |
not_affected
(fixed in bzip2 1.0.8)
|
||
| CVE-2016-3189 |
not_affected
(vulnerability is in tool that we do not compile)
|
||
| CVE-2011-4089 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2010-0405 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2008-1372 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2005-1260 |
not_affected
(fixed in bzip2 1.0.3)
|
||
| CVE-2005-0953 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2002-0761 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2002-0760 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| CVE-2002-0759 |
not_affected
(1.0.8 does not match CVE configuration.)
|
||
| cld2 |
|
||
| flashsdk | 1.0 |
|
|
| freetype | 2.13.3 | CVE-2026-61860 |
needs_triage
|
| CVE-2026-50811 |
needs_triage
|
||
| CVE-2026-23865 |
needs_triage
|
||
| CVE-2025-27363 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2025-23022 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2022-27406 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2022-27405 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2022-27404 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2020-15999 |
not_affected
(unaffected, png compressed glyph support is not enabled)
|
||
| CVE-2018-6942 |
not_affected
(unaffected, introduced in later build)
|
||
| CVE-2017-8287 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2017-8105 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2017-7864 |
not_affected
(unaffected, introduced in later build (2.7.1))
|
||
| CVE-2017-7858 |
not_affected
(unaffected, introduced in later build)
|
||
| CVE-2017-7857 |
not_affected
(unaffected, introduced in later build)
|
||
| CVE-2016-10328 |
not_affected
(unaffected, only affected head for about a day)
|
||
| CVE-2016-10244 |
not_affected
(Does not exist in FreeType 2.13.3)
|
||
| CVE-2015-9383 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2015-9382 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2015-9381 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2015-9290 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9747 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9746 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9745 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9675 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9674 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9673 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9672 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9671 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9670 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9669 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9668 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9667 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9666 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9665 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9664 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9663 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9662 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9661 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9660 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9659 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9658 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9657 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-9656 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-2241 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2014-2240 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-5670 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-5669 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-5668 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1144 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1143 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1142 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1141 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1140 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1139 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1138 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1137 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1136 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1135 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1134 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1133 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1132 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1131 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1130 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1129 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1128 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1127 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2012-1126 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2011-2895 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-3855 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-3814 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-3311 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-3054 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-3053 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2808 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2807 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2806 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2805 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2541 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2527 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2520 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2519 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2500 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2499 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2498 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2010-2497 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2009-0946 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2008-1808 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2008-1807 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2008-1806 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2007-3506 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2007-2754 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2006-3467 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2006-2661 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2006-1861 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| CVE-2006-0747 |
not_affected
(2.13.3 does not match CVE configuration.)
|
||
| giflib | 5.2.1 | CVE-2026-26740 |
not_affected
(5.2.1 does not match CVE configuration.)
|
| CVE-2026-23868 |
needs_triage
|
||
| CVE-2025-31344 |
not_affected
(not-exploitable: issue is in gif2rgb cli, not the library)
|
||
| CVE-2024-45993 |
not_affected
(not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue)
|
||
| CVE-2023-48161 |
not_affected
(not-exploitable: issue is in gif2rgb cli, not the library. The POC file attached to the CVE passes through all modes without issue)
|
||
| CVE-2023-39742 |
not_affected
(not-exploitable: issue is in gif2rgb cli, not the library)
|
||
| CVE-2022-28506 |
not_affected
(not-exploitable: issue is in gif2rgb cli, not the library)
|
||
| CVE-2021-40633 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2020-23922 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2019-15133 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2018-11490 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2018-11489 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2016-3977 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2016-3177 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| CVE-2015-7555 |
not_affected
(5.2.1 does not match CVE configuration.)
|
||
| international_components_for_unicode | 58.1 | CVE-2025-5222 |
not_affected
(Vulnerability exists in genrb CLI tool build process, not in the ICU library itself. Document Filters does not use the genrb binary or the affected parsing code during runtime operation.)
|
| CVE-2020-21913 |
not_affected
(vulnerability is in build tool (pkgdata.cpp), which is not used by DF.)
|
||
| CVE-2020-10531 |
resolved
(Patched applied from https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca)
|
||
| CVE-2018-18928 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2017-17484 |
not_affected
(Unused code block. Only occurs when converting from UTF8 to UTF8 which is avoided for performance reasons)
|
||
| CVE-2017-15422 |
resolved
(Patched applied from https://github.com/unicode-org/icu/commit/71dd84d4ffd6600a70e5bca56a22b957e6642bd4)
|
||
| CVE-2017-15396 |
resolved
(Patched applied from https://chromium.googlesource.com/chromium/deps/icu/+/7f873c45c23fa1baf1a1d90f449c5c4c34bd8ba6)
|
||
| CVE-2017-14952 |
resolved
(Patched applied from https://github.com/unicode-org/icu/commit/7c31981bd009a5ebc2e93f7f67a0331cd777cfa4)
|
||
| CVE-2017-7868 |
resolved
(Patched applied from https://github.com/unicode-org/icu/commit/35a07bf89d64809b2e9af3cc90b53e3261677c53)
|
||
| CVE-2017-7867 |
resolved
(Patched applied from https://github.com/unicode-org/icu/commit/35a07bf89d64809b2e9af3cc90b53e3261677c53)
|
||
| CVE-2016-7415 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2016-6293 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2015-5922 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-9911 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-9654 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-8147 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-8146 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7940 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7926 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2014-7923 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2011-4599 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2007-4771 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| CVE-2007-4770 |
not_affected
(58.1 does not match CVE configuration.)
|
||
| libjpeg | 9e | CVE-2026-75466 |
needs_triage
|
| CVE-2026-24797 |
needs_triage
|
||
| CVE-2026-13708 |
needs_triage
|
||
| CVE-2023-37837 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2023-37836 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-37770 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-37769 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-37768 |
not_affected
(CVE impacts thorfdbg/libjpeg not ijg libjpeg)
|
||
| CVE-2022-35166 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-32978 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-32202 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-32201 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-31796 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2022-31620 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39520 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39519 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39518 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39517 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39516 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39515 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2021-39514 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2020-14153 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2020-14152 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2018-11813 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2018-11214 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2018-11213 |
not_affected
(9e does not match CVE configuration.)
|
||
| CVE-2018-11212 |
not_affected
(9e does not match CVE configuration.)
|
||
| leptonica | 1.84.1 | CVE-2022-38266 |
not_affected
(1.84.1 does not match CVE configuration.)
|
| CVE-2020-36280 |
not_affected
(Unused code block. Issues is in leptonica's TIFF reader which is not used.)
|
||
| CVE-2018-7442 |
not_affected
(Unused code block. gplot writer)
|
||
| CVE-2018-7441 |
not_affected
(Unused code block. Covers temp file in utility programs)
|
||
| CVE-2018-7440 |
not_affected
(Unused code block. gplot writer)
|
||
| CVE-2018-7247 |
not_affected
(Unused code block. pixHtmlViewer)
|
||
| CVE-2018-7186 |
not_affected
(Unused code block. Occurs is gplot reader)
|
||
| CVE-2018-3836 |
not_affected
(1.84.1 does not match CVE configuration.)
|
||
| CVE-2017-18196 |
not_affected
(1.84.1 does not match CVE configuration.)
|
||
| libpng | 1.6.40 | CVE-2026-64612 |
not_affected
(The defect is in libcupsfilters'/cups-filters' own PNG-reading caller code (_cfImageReadPNG / _cupsImageReadPNG in cupsfilters/image-png.c), not in libpng itself; libpng behaves correctly, but the CUPS filter never installs an error handler or setjmp recovery frame around png_create_read_struct(). Document Filters does not vendor, build, or link libcupsfilters or cups-filters (no external/ entry, no CMake reference, no CUPS print-filter integration anywhere in the codebase), so this caller-side defect is never exercised. Document Filters' own libpng call sites (filters/isysgraphics/source/ISYSimage.cpp) correctly install a custom error callback and setjmp(png_jmpbuf(...)) recovery around png_create_read_struct, so even the underlying unsafe pattern is not repeated here.)
|
| CVE-2026-40930 |
not_affected
(The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser's inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.)
|
||
| CVE-2026-34757 |
needs_triage
|
||
| CVE-2026-33636 |
needs_triage
|
||
| CVE-2026-33416 |
needs_triage
|
||
| CVE-2026-25646 |
needs_triage
|
||
| CVE-2026-22801 |
needs_triage
|
||
| CVE-2026-22695 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2026-3713 |
not_affected
(The vulnerability is in the contrib/pngminus/pnm2png CLI tool (contrib/pngminus/pnm2png.c), which is a standalone conversion utility shipped with the libpng source distribution. Document Filters builds libpng as an OBJECT library using only the core library source files and does not compile any contrib/ tools. The pnm2png binary is never built, linked, or invoked.)
|
||
| CVE-2025-66293 |
needs_triage
|
||
| CVE-2025-65018 |
needs_triage
|
||
| CVE-2025-64720 |
needs_triage
|
||
| CVE-2025-64506 |
needs_triage
|
||
| CVE-2025-64505 |
needs_triage
|
||
| CVE-2025-28164 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2025-28162 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2021-4214 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2019-7317 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2019-6129 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2018-14550 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2018-14048 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2018-13785 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2017-12652 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2016-10087 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2016-3751 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2015-8540 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2015-8472 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2015-8126 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2015-7981 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2015-0973 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2014-9495 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2014-0333 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2013-7354 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2013-7353 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2013-6954 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2012-3425 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-3464 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-3328 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-3048 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-3045 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-2692 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-2691 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-2690 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-2501 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2011-0408 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2010-2249 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2010-1205 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2010-0205 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2009-5063 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2009-2042 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2009-0040 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2008-6218 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2008-5907 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2008-3964 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2008-1382 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2007-5269 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2007-5268 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2007-5267 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2007-5266 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2006-7244 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2006-5793 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2006-3334 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2006-0481 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2004-0599 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2004-0598 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2004-0597 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2004-0421 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2002-1363 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2002-0728 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| CVE-2002-0660 |
not_affected
(1.6.40 does not match CVE configuration.)
|
||
| libtiff | 4.6.0 | CVE-2026-70651 |
needs_triage
|
| CVE-2026-52492 |
needs_triage
|
||
| CVE-2026-52491 |
needs_triage
|
||
| CVE-2026-52490 |
needs_triage
|
||
| CVE-2026-12912 |
not_affected
(The overflow in PixarLogDecode (tif_pixarlog.c) is only reachable when the application explicitly selects the PIXARLOGDATAFMT_8BITABGR output format by calling TIFFSetField(tif, TIFFTAG_PIXARLOGDATAFMT, PIXARLOGDATAFMT_8BITABGR). Document Filters never sets TIFFTAG_PIXARLOGDATAFMT anywhere in its codebase; its TIFF decoder (filters/isysgraphics/source/ISYStiff_decoder.cpp) reads pixels only via TIFFReadScanline and TIFFReadRGBAImageOriented. libtiff's default format selection (PixarLogGuessDataFmt) never returns PIXARLOGDATAFMT_8BITABGR, and per the upstream advisory TIFFRGBAImageBegin/TIFFReadRGBAImage do not select this format either. The vulnerable code path is therefore never exercised.)
|
||
| CVE-2026-4775 |
needs_triage
|
||
| CVE-2025-61145 |
not_affected
(The double-free vulnerability is in the tiffcrop CLI tool (tools/tiffcrop.c:2931), triggered in main() when freeing buffers after a failed image inversion. Document Filters does not compile or ship tiffcrop; only the libtiff library sources are included. The vulnerable tool code is not present in the build.)
|
||
| CVE-2025-61144 |
not_affected
(The vulnerability is entirely in the tiffcrop CLI tool (tools/tiffcrop.c) in functions readSeparateStripsIntoBuffer and combineSeparateSamplesBytes. Document Filters does not compile or ship tiffcrop; only the libtiff library sources are included. The function readSeparateStripsIntoBuffer is not present in the Document Filters build.)
|
||
| CVE-2025-61143 |
not_affected
(The vulnerability is in the tiffcrop CLI tool (tools/tiffcrop.c:2954) which passes a NULL TIFF* to TIFFFileName(). Document Filters does not compile or ship the tiffcrop CLI utility; only the libtiff library sources are included. The vulnerable tool code is not present in the build.)
|
||
| CVE-2025-9900 |
needs_triage
|
||
| CVE-2025-9165 |
not_affected
(The vulnerable code is in tools/tiffcmp.c which is not compiled into Document Filters.)
|
||
| CVE-2025-8961 |
not_affected
(Document Filters vendors libtiff 4.6.0 and does not compile or ship the tiffcrop CLI utility (tools/tiffcrop.c not part of build; no tiffcrop objects found in build output). CVE only impacts tiffcrop in 4.7.0 per NVD/VulDB advisory; our version predates affected release and excludes the tool, making the vulnerable code unreachable.)
|
||
| CVE-2025-8851 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2025-8534 |
not_affected
(Vulnerability is in tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2025-8177 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2025-8176 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2024-13978 |
not_affected
(Vulnerability is in a tiff CLI tool; code is not compiled into Document Filters.)
|
||
| CVE-2024-7006 |
resolved
(Patched applied from https://gitlab.com/libtiff/libtiff/-/commit/3705f82b6483c7906cf08cd6b9dcdcd59c61d779)
|
||
| CVE-2023-52356 |
resolved
(Patched applied from https://gitlab.com/libtiff/libtiff/-/merge_requests/546)
|
||
| CVE-2023-52355 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2023-41175 |
not_affected
(Vulnerability is in tiff CLI tool raw2tiff; code is not compiled into Document Filters.)
|
||
| CVE-2023-40745 |
not_affected
(Vulnerability is in tiff CLI tool tiffcp; code is not compiled into Document Filters.)
|
||
| CVE-2023-30775 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2023-30774 |
not_affected
|
||
| CVE-2023-30086 |
not_affected
(Vulnerability is in tiff CLI tool tiffcp; code is not compiled into Document Filters.)
|
||
| CVE-2023-26966 |
not_affected
|
||
| CVE-2023-26965 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25435 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25434 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-25433 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2023-3618 |
not_affected
(The issue only exists in the tiffcrop CLI tool, and is due to how it ignoring error state when calling the libtiff API. Document Filters does not have the same logic error in it's calling code to libtiff, and therefore not impacted.)
|
||
| CVE-2023-3576 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-3316 |
not_affected
|
||
| CVE-2023-3164 |
not_affected
(Vulnerability is present in one of tiff tools files, which we do not compile.)
|
||
| CVE-2023-2908 |
not_affected
|
||
| CVE-2023-2731 |
not_affected
(Issue was introduced post 4.3.0.)
|
||
| CVE-2023-1916 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0804 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0803 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0802 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0801 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.)
|
||
| CVE-2023-0800 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0799 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0798 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0797 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.)
|
||
| CVE-2023-0796 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2023-0795 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-48281 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-40090 |
not_affected
(Document Filters detects and protects against circular references in the TIFF directory outside of libtiff, mitigating this issue.)
|
||
| CVE-2022-34526 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-22844 |
not_affected
(vulnerability is in tiff tools (specifically tiffset), example files which we do not compile.)
|
||
| CVE-2022-4645 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3970 |
not_affected
(Unused code block. Occurs in TIFFReadRGBATileExt. The code is currently unused but fix was still applied from libtiff commit: https://gitlab.com/libtiff/libtiff/-/commit/227500897dfb07fb7d27f7aa570050e62617e3be)
|
||
| CVE-2022-3627 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3626 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3599 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3598 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3597 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-3570 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2953 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2869 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2868 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2867 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-2521 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2520 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2519 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2058 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2057 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-2056 |
not_affected
(Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters.)
|
||
| CVE-2022-1623 |
not_affected
(Issue was introduced post 4.3.0.)
|
||
| CVE-2022-1622 |
not_affected
(Issue was introduced post 4.3.0.)
|
||
| CVE-2022-1355 |
not_affected
(Vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-1354 |
not_affected
|
||
| CVE-2022-1210 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-1056 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0924 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0909 |
not_affected
|
||
| CVE-2022-0908 |
not_affected
|
||
| CVE-2022-0907 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0891 |
not_affected
(vulnerability is in tiff tools, example files which we do not compile.)
|
||
| CVE-2022-0865 |
not_affected
|
||
| CVE-2022-0562 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2022-0561 |
not_affected
|
||
| CVE-2020-35524 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-35523 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-35522 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-35521 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-19144 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-19143 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-19131 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2020-18768 |
not_affected
(The impacted code is not in the version of libtiff used by Document Filters.)
|
||
| CVE-2019-17546 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2019-14973 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2019-7663 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2019-6128 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-19210 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-18661 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-18557 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17795 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17101 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17100 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-17000 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-16335 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-15209 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-12900 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-10963 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-10801 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2018-10779 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2018-10126 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-8905 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-7456 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-5784 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2018-5360 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2017-18013 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17973 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17942 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-17095 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-16232 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-13727 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-13726 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-12944 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-11613 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-11335 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-10688 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9937 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9936 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9935 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9815 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9404 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9403 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9147 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-9117 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7602 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7601 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7600 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7599 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7598 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7597 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7596 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7595 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7594 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7593 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-7592 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-5563 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2017-5225 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10371 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10272 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10271 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10270 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10269 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10268 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10267 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10266 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10095 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10094 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10093 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-10092 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9540 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9539 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9538 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9537 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9536 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9535 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9534 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9533 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9532 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9453 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2016-9448 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9297 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-9273 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-8331 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-6223 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5652 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5323 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5322 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5321 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5319 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5318 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5317 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5316 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5315 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5314 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-5102 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3991 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3990 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3945 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3658 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3634 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3633 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3632 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3631 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3625 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3624 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3623 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3622 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3621 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3620 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3619 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2016-3186 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8870 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8784 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2015-8783 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2015-8782 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2015-8781 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2015-8683 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8668 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-8665 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-7554 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2015-7313 |
not_affected
(vulnerability is in libtiff versions below 4.0.7. https://security.gentoo.org/glsa/201701-16)
|
||
| CVE-2015-1547 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-9655 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2014-9330 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8130 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8129 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2014-8127 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-4244 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-4231 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2013-1961 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2013-1960 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2012-5581 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-4564 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-4447 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-3401 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-2113 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2012-2088 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2012-1173 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2011-1167 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-4665 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2631 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2630 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2597 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2596 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2595 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2483 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2482 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2481 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2443 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2233 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2067 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2010-2065 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2009-5022 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2009-2347 |
not_affected
(code is not compiled into Document Filters.)
|
||
| CVE-2009-2285 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2008-2327 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3465 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3464 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3463 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3462 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3461 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-3460 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2656 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2193 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2120 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2026 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2025 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-2024 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2006-0405 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2005-2452 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2005-1544 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-1308 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-1307 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-1183 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-0929 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-0886 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-0804 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| CVE-2004-0803 |
not_affected
(4.6.0 does not match CVE configuration.)
|
||
| libwebp | 1.3.2 | CVE-2026-58586 |
not_affected
(This CVE is against the Image::WebP Perl/CPAN module (distributed by ZAPAD on CPAN), which bundles its own private, unrelated copy of libwebp 0.3.0 from 2013. Document Filters has no Perl bindings and does not vendor, build, or depend on Image::WebP or any CPAN module (confirmed: no Image::WebP/CPAN references anywhere in the codebase). Document Filters vendors the official upstream libwebp 1.3.2 directly from webmproject/libwebp, which is a completely separate codebase from the module's bundled fork and is already recorded as not_affected by the underlying CVE-2023-4863 in this same vulnerabilities block.)
|
| CVE-2023-4863 |
not_affected
(Does not exist in libwebp 1.3.2)
|
||
| CVE-2023-1999 |
not_affected
(Does not exist in libwebp 1.3.2)
|
||
| CVE-2020-36332 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2020-36331 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2020-36330 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2020-36329 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2020-36328 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25014 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25013 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25012 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25011 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25010 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2018-25009 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2016-9969 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| CVE-2016-9085 |
not_affected
(1.3.2 does not match CVE configuration.)
|
||
| litehtml | 0.3 |
|
|
| 7-zip | 23.01 | CVE-2026-58052 |
not_affected
(The vulnerability requires two conditions that Document Filters does not satisfy. First, it lives in the RAR5 STM (alternate data stream) record handling of the full 7-Zip application; the LZMA SDK 23.01 that Document Filters consumes ships no RAR handler (its Archive directory contains only the 7z, LZMA, XZ, and Split handlers), and RAR files are instead processed by the separate unrar 5.9.1 library. Second, the Mark-of-the-Web / Zone.Identifier propagation logic that the flaw defeats resides in the 7-Zip extraction UI layer (CPP/7zip/UI/Common/ArchiveExtractCallback.cpp), which is not part of the Document Filters build source list in external/CMakeLists.txt. Document Filters uses the SDK only as an in-memory decompression library and never writes NTFS Zone.Identifier or alternate data streams to disk. The vulnerable code is therefore neither compiled nor reachable. The issue is additionally Windows/NTFS-specific.)
|
| CVE-2026-48112 |
not_affected
(The vulnerability exists in the Ar handler (ParseLibSymbols in ArHandler.cpp), which parses Unix ar archives and BSD-style __.SYMDEF symbol tables and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; ArHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable ParseLibSymbols function is therefore never compiled or reachable.)
|
||
| CVE-2026-48111 |
not_affected
(The vulnerability exists in the UEFI firmware image handler (ParseDepedencyExpression / kExpressionCommands in UefiHandler.cpp), which parses UEFIc and UEFIf firmware volumes and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable ParseDepedencyExpression function is therefore never compiled or reachable.)
|
||
| CVE-2026-48104 |
not_affected
(The vulnerability exists in the SquashFS handler (OpenDir / _blockToNode / _nodesPos in SquashfsHandler.cpp), which is part of the full 7-Zip application and is not present in the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; SquashfsHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenDir function and the _blockToNode/_nodesPos structures are therefore never compiled or reachable.)
|
||
| CVE-2026-48103 |
not_affected
(The vulnerability exists in the WIM (Windows Imaging) archive handler (CHandler::GetSecurity / SecurOffsets in WimHandler.cpp), which is part of the full 7-Zip application and is not present in the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; WimHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable GetSecurity function and the SecurOffsets table are therefore never compiled or reachable, and the .wim/.swm/.esd/.ppkg formats the handler registers for are not processed by Document Filters.)
|
||
| CVE-2026-48102 |
not_affected
(The vulnerability exists in the UDF disc image handler (CFileId::Parse in UdfIn.cpp), which parses UDF file systems (.iso and .udf images) and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; the Archive/Udf directory and UdfIn.cpp do not exist in the SDK distribution and are not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable CFileId::Parse function is therefore never compiled or reachable, and the .iso/.udf formats the handler registers for are not processed by Document Filters.)
|
||
| CVE-2026-48101 |
not_affected
(The vulnerability exists in the UEFI firmware image handler (OpenCapsule / GetStream in UefiHandler.cpp), which parses UEFI capsule (.scap) and firmware volume (.uefif) images and is part of the full 7-Zip application, not the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; UefiHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt, which compiles only the 7z, LZMA, and XZ handlers). The vulnerable OpenCapsule function is therefore never compiled or reachable, and the .scap/.uefi formats the handler registers for are not processed by Document Filters.)
|
||
| CVE-2026-48095 |
not_affected
(The vulnerability exists in the NTFS handler (CInStream::GetCuSize in NtfsHandler.cpp), which is part of the full 7-Zip application and is not present in the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; NtfsHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt). The vulnerable GetCuSize function is therefore never compiled or reachable.)
|
||
| CVE-2026-48092 |
not_affected
(The vulnerability exists in the SquashFS handler (ReadBlock in SquashfsHandler.cpp), which is part of the full 7-Zip application and is not present in the LZMA SDK. Document Filters consumes LZMA SDK 23.01, whose Archive directory ships only the 7z, LZMA, XZ, and Split handlers; SquashfsHandler.cpp does not exist in the SDK distribution and is not included in the Document Filters build source list (external/CMakeLists.txt). The vulnerable ReadBlock function is therefore never compiled or reachable. Additionally, the flaw is exploitable only on 32-bit builds where size_t is 32 bits; Document Filters ships 64-bit builds where the offsetInBlock + blockSize addition is promoted to 64 bits and the bounds check correctly rejects the input.)
|
||
| CVE-2026-14266 |
needs_triage
|
||
| CVE-2025-55188 |
not_affected
(Document Filters is not affected because the vulnerable code path is never invoked. The product requires callers to provide an explicit, validated extraction path and does not use p7zip to directly create files on the system. These runtime protections prevent exploitation of the symbolic link handling issue.)
|
||
| CVE-2025-53817 |
not_affected
(Document Filters does not compile the affected code.)
|
||
| CVE-2025-53816 |
not_affected
(The vulnerability exists in the RAR5 decoder (NCompress::NRar5::CDecoder) which is part of the full 7-Zip application, not the LZMA SDK. Document Filters uses LZMA SDK 23.01 which does not include any RAR handlers. RAR file processing is handled by a separate unrar library (version 5.9.1). The LZMA SDK build only includes handlers for 7z, LZMA, XZ, and various compression codecs, but no RAR-related code.)
|
||
| CVE-2025-11002 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2025-0411 |
not_affected
(The issue exists in the full 7-zip tool; the impacted source is not in the the LZMA SDK. Document Filters is not impacted.)
|
||
| CVE-2024-11612 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2024-11477 |
not_affected
(The issue exists in the full 7-zip tool; the impacted source is not in the the LZMA SDK. Document Filters is not impacted.)
|
||
| CVE-2023-40481 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2022-47112 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2022-47111 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2018-10172 |
not_affected
(The issue exists in the 7-zip desktop application and how it was compiled by the vendor. It does not impact the 7-zip/LZMA SDK which Document Filters consumes.)
|
||
| CVE-2018-10115 |
not_affected
(The issue exists in the full 7-zip tool; the impacted source is not in the the LZMA SDK. Document Filters is not impacted.)
|
||
| CVE-2018-5996 |
not_affected
(The issue exists in the full 7-zip tool; the impacted source is not in the the LZMA SDK. Document Filters is not impacted.)
|
||
| CVE-2017-17969 |
not_affected
(The issue exists in the full 7-zip tool; the impacted source is not in the the LZMA SDK. Document Filters is not impacted.)
|
||
| CVE-2016-7804 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2016-2335 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2016-2334 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2008-6536 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2007-4725 |
not_affected
(23.01 does not match CVE configuration.)
|
||
| CVE-2005-3051 |
false_positive
(Unknown vendors 'igor_pavlov')
|
||
| protobuf | 3.0.0 | CVE-2026-67198 |
needs_triage
|
| CVE-2026-67195 |
needs_triage
|
||
| CVE-2026-55407 |
needs_triage
|
||
| CVE-2026-55406 |
needs_triage
|
||
| CVE-2026-52878 |
needs_triage
|
||
| CVE-2026-48599 |
needs_triage
|
||
| CVE-2026-40027 |
needs_triage
|
||
| CVE-2026-6409 |
needs_triage
|
||
| CVE-2026-0994 |
needs_triage
|
||
| CVE-2025-53605 |
not_affected
(Vulnerability only affects rust protobuf code, those parts are not incorporated into Document Filters.)
|
||
| CVE-2024-24786 |
not_affected
(Vulnerability requires access to Unmarshal, which is not reachable in Document Filters.)
|
||
| CVE-2024-7254 |
not_affected
(Vulnerability only affects java protobuf code, those parts are not incorporated into Document Filters.)
|
||
| CVE-2024-2410 |
not_affected
(3.0.0 does not match CVE configuration.)
|
||
| CVE-2023-24535 |
false_positive
(Unknown vendors 'protobuf')
|
||
| CVE-2021-22570 |
not_affected
(Vulnerability does not affect runtime serialization/deserialization. The issue happens when generating code with the protoc compiler, which does not happen at runtime.)
|
||
| CVE-2021-3121 |
false_positive
(Unknown vendors 'golang, hashicorp')
|
||
| CVE-2015-5237 |
not_affected
(Vulnerability is in serialization, and we only de-serialize.)
|
||
| protobuf-c | 1.3.3 | CVE-2022-48468 |
resolved
(Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82)
|
| CVE-2022-33070 |
not_affected
(1.3.3 does not match CVE configuration.)
|
||
| sfntly | r239 | CVE-2016-1709 |
resolved
(Patched applied from https://github.com/googlefonts/sfntly/commit/c56b85408bab232efd7e650f0994272a174e3b92)
|
| skia | CVE-2026-79147 |
needs_triage
|
|
| CVE-2026-79144 |
needs_triage
|
||
| CVE-2026-79112 |
needs_triage
|
||
| CVE-2026-79020 |
needs_triage
|
||
| CVE-2026-78958 |
needs_triage
|
||
| CVE-2013-6648 |
resolved
(Patched applied from https://skia.googlesource.com/skia/+/73be1fc2b02757e3d98621d7cf735591aa6dffdb)
|
||
| skia-svg |
|
||
| snappy | 1.1.3 | CVE-2026-49359 |
needs_triage
|
| CVE-2026-49358 |
needs_triage
|
||
| CVE-2026-49286 |
needs_triage
|
||
| CVE-2026-49260 |
needs_triage
|
||
| CVE-2026-46683 |
needs_triage
|
||
| CVE-2026-46643 |
needs_triage
|
||
| CVE-2026-44302 |
needs_triage
|
||
| CVE-2025-65942 |
not_affected
(This CVE affects VictoriaMetrics, a time series monitoring solution. We use Google Snappy compression library directly; VictoriaMetrics is not present in Document Filters.)
|
||
| CVE-2024-36124 |
false_positive
(Unknown vendors 'dain')
|
||
| CVE-2024-36114 |
not_affected
(The issue is related to Aircompressor, Java port of (among the others) Snappy. We use Snappy directly; Document Filters is not impacted.)
|
||
| CVE-2023-41330 |
false_positive
(Unknown vendors 'knplabs')
|
||
| CVE-2023-28115 |
false_positive
(Issue does not exist in Google Snappy library, but in an unrelated PHP library not used by DocFilters)
|
||
| CVE-2018-7577 |
not_affected
(1.1.3 does not match CVE configuration.)
|
||
| stackwalker | 13 |
|
|
| teigha | 4.0.0 |
|
|
| tesseract | 3.02.02 | CVE-2026-73067 |
needs_triage
|
| CVE-2026-73066 |
needs_triage
|
||
| CVE-2025-60176 |
not_affected
(Document Filter does not use the Tesseract WordPress plugin)
|
||
| CVE-2022-38266 |
not_affected
(3.02.02 does not match CVE configuration.)
|
||
| CVE-2019-25257 |
not_affected
(LogicalDOC Enterprise is not used in our product. Our Hyland DocumentFilters is a document processing SDK/API, completely different from LogicalDOC's document management server application. The vulnerability is in LogicalDOC's configuration of the ocr.Tesseract.path parameter, not in Tesseract itself.)
|
||
| CVE-2011-1136 |
not_affected
(3.02.02 does not match CVE configuration.)
|
||
| tinyspline | 0.6.0 |
|
|
| unrar | 5.9.1 | CVE-2026-14191 |
not_affected
(The vulnerable function RecVolumes5::ReadHeader in recvol5.cpp is compiled into the product (recvol.cpp #includes recvol5.cpp), but the recovery-volume (.rev) code path is unreachable in Document Filters. Every entry point into it -- RecVolumesTest (extract.cpp:124 and :225) and RecVolumesRestore (extract.cpp:339 and volume.cpp:90) -- is guarded by preprocessor conditions that exclude the code when RARDLL is defined ('#if !defined(SFX_MODULE) && !defined(RARDLL)' and '#ifndef RARDLL'). Document Filters builds unrar with RARDLL defined (external/CMakeLists.txt) and drives the library exclusively through the DLL API (RAROpenArchiveEx followed by RARProcessFile RAR_TEST/RAR_SKIP in filters/isysreaders/readers/ReaderRAR.cpp). It never performs a recovery, repair, or .rev test operation, so RecVolumes5::ReadHeader is never called and the out-of-bounds write cannot be triggered.)
|
| CVE-2025-60835 |
not_affected
(This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable 'unrar.dll' referenced in the advisory is IZArc's own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.)
|
||
| CVE-2022-48579 |
not_affected
(The problem arises within the unrar library when employing its API to unpack the archive's contents into a designated directory. Document Filters does not make use of these functions while handling rar files, and as a result, is not affected by this problem.)
|
||
| CVE-2017-14122 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-14121 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-14120 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-12942 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-12941 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-12940 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2017-12938 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2012-6706 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2007-3726 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| CVE-2007-0855 |
not_affected
(5.9.1 does not match CVE configuration.)
|
||
| wavpack | 5.6.0 | CVE-2026-53705 |
needs_triage
|
| CVE-2022-2476 |
not_affected
(not-exploitable: issue is in cli tool, not library)
|
||
| CVE-2021-44269 |
not_affected
(not-exploitable: WavpackPackSamples is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2020-35738 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2019-1010319 |
not_affected
(not-exploitable: ParseWave64HeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2019-1010317 |
not_affected
(not-exploitable: ParseCaffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2019-1010315 |
not_affected
(not-exploitable: ParseDsdiffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2019-11498 |
not_affected
(not-exploitable: WavpackSetConfiguration64/pack_utils.c is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-19841 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2018-19840 |
not_affected
(not-exploitable: WavpackPackInit/pack_utils.c is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-10540 |
not_affected
(not-exploitable: ParseWave64HeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-10539 |
not_affected
(not-exploitable: ParseDsdiffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-10538 |
not_affected
(not-exploitable: ParseRiffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-10537 |
not_affected
(not-exploitable: ParseWave64HeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-10536 |
not_affected
(not-exploitable: ParseRiffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-7254 |
not_affected
(not-exploitable: ParseCaffHeaderConfig is not compiled in; used for WAVPACK creation.)
|
||
| CVE-2018-7253 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2018-6767 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2016-10172 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2016-10171 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2016-10170 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| CVE-2016-10169 |
not_affected
(5.6.0 does not match CVE configuration.)
|
||
| zlib | 1.3 | CVE-2026-77640 |
needs_triage
|
| CVE-2026-77639 |
needs_triage
|
||
| CVE-2026-74767 |
needs_triage
|
||
| CVE-2026-70631 |
not_affected
(The vulnerable code is FFmpeg's own TIFF decoder (tiff_unpack_zlib() in libavcodec/tiff.c), which ignores the actual uncompress() output length and memcpy()s all declared rows out of a partially-initialized heap buffer -- the defect is in FFmpeg's application-level handling of zlib's result, not in zlib itself. Document Filters does not vendor, build, or link FFmpeg/libavcodec/libavformat in any form; no FFmpeg, tiff_unpack_zlib, or libavcodec reference exists anywhere in this codebase, so the vulnerable code is never compiled in. Document Filters decodes Deflate-compressed TIFF strips through libtiff 4.6.0 (external/libtiff-4.6.0/tif_zip.c, used by filters/isysgraphics/source/ISYStiff_decoder.cpp), whose ZIPDecode() already performs the equivalent check the FFmpeg fix adds: after the inflate loop it verifies the full expected output count was produced and, if bytes remain, raises 'Not enough data at scanline %lu (short %PRIu64 bytes)' and returns failure rather than emitting the uninitialized tail of the buffer.)
|
||
| CVE-2026-70630 |
not_affected
(The vulnerable code is FFmpeg's own Screenpresso SPV1 video decoder (screenpresso_decode_frame() in libavcodec/screenpresso.c), which ignores the actual output length returned by zlib's uncompress() and hands the full frame geometry to av_image_copy_plane() out of a partially-initialized persistent heap buffer -- the defect is in FFmpeg's application-level handling of zlib's result, not in zlib itself, and the upstream fix touches only libavcodec/screenpresso.c with no change to any zlib source file. Document Filters does not vendor, build, or link FFmpeg/libavcodec/libavformat in any form and implements no video codec of any kind; no FFmpeg, screenpresso, SPV1, inflated_buf, or av_image_copy_plane reference exists anywhere in this codebase, so the vulnerable code is never compiled in. Document Filters does identify and read AVI containers (ISYS_NS::ID::avi_video, filters/isysreaders/readers/ReaderAVI.cpp), but CAVIReader::LoadDocument() is a metadata-only RIFF header parser: it walks the 'hdrl'/'strl' header lists to emit stream, frame-rate, resolution, and audio-format metadata, then returns without reading the 'movi' chunk at all ('Ignore the rest of the file, including any idxl'). It never inspects a stream's fccHandler to dispatch a codec, never allocates a frame buffer, and never invokes zlib on packet payloads, so a crafted SPV1 packet carrying a short deflate stream is never decompressed or copied by Document Filters.)
|
||
| CVE-2026-66913 |
not_affected
(The vulnerable code is Lookyloo's own capture-archive/HAR import handling (a standalone Python web application by CIRCL), not zlib itself. Document Filters does not vendor, build, or run any Lookyloo code and has no capture-archive or HAR-import feature; the CVE's application-level defect is never exercised regardless of how Document Filters' own zlib-based ZIP/gzip decompression (shared/core/source/ISYSzlib.cpp, ISYSzipfile.cpp, filters/isysreaders/readers/ReaderGz.cpp) behaves.)
|
||
| CVE-2026-63825 |
not_affected
(CVE-2026-63825 is a Linux kernel vulnerability, not a userspace zlib vulnerability. The 'zlib_inflate' referenced in the advisory is the Linux kernel's own internal, independently-maintained decompressor (lib/zlib_inflate/ in the kernel source tree), a different codebase from the userspace madler/zlib 1.3 that Document Filters vendors -- the two share no source. The root cause requires a kernel built with GCOV coverage instrumentation (CONFIG_GCOV_KERNEL) plus the IPComp/IPsec network-compression subsystem processing attacker-controlled traffic on a multi-CPU system. Document Filters is a userspace C++ SDK with .NET/Python/Java bindings; it does not build, ship, or modify a Linux kernel, does not enable kernel GCOV instrumentation, and does not implement or use IPsec/IPComp in any form. No kernel module, GCOV kernel-build configuration, or IPComp/xfrm code exists anywhere in this codebase.)
|
||
| CVE-2026-62292 |
needs_triage
|
||
| CVE-2026-58107 |
needs_triage
|
||
| CVE-2026-58045 |
not_affected
(CVE-2026-58045 is a defect in the Node.js runtime's own zlib binding layer, not in the zlib library. The upstream fix (nodejs/node commit 0d072480c3dbbad6db8723e39786321646989343) changes only src/node_zlib.cc, replacing two CHECK(Buffer::IsWithinBounds(...)) assertions in CompressionStream::Write with THROW_ERR_OUT_OF_RANGE so a JavaScript object with a spoofed byteLength getter raises a RangeError instead of aborting the process; no zlib source file is touched. That the affected surface includes zlib.brotliCompressSync, zlib.brotliDecompressSync, zlib.zstdCompressSync, and zlib.zstdDecompressSync -- codecs zlib does not implement -- further confirms the defect lives in Node's shared binding wrapper rather than in zlib. Document Filters is a C++ SDK with .NET/Python/Java bindings; it embeds no Node.js runtime, no V8, and no N-API/NAN addon, so the vulnerable CompressionStream::Write code and the V8 TypedArray spoofing primitive it depends on are not present in the tree at all (no node_zlib.cc, no Buffer::IsWithinBounds, no THROW_ERR_OUT_OF_RANGE). Document Filters calls zlib's C API directly from shared/core/source/ISYScompressedstream.cpp and ISYSzipfile.cpp with buffer offsets and lengths it computes itself in native code, where no spoofable byteLength accessor exists. The only package.json in the repository (filters/tools/isys_readergen) is an internal build-time code generator depending solely on @types/node and commander; it is not shipped, does not use node:zlib, and no Node.js runtime is redistributed with the product.)
|
||
| CVE-2026-53430 |
needs_triage
|
||
| CVE-2026-44254 |
needs_triage
|
||
| CVE-2026-43970 |
false_positive
(CVE-2026-43970 is a vulnerability in cowlib (ninenines/cowlib), an Erlang HTTP support library, not in the zlib C library. The flaw is in cow_spdy.erl, which calls Erlang's zlib:inflate/2 against attacker-controlled SPDY-compressed headers without any output-size limit. The upstream fix (commit 16aad3fb9f81f5cda4d1706ff0c54237c619c282) deletes the entire cow_spdy module and contains no C code changes. The 'zlib' association exists only because cow_spdy used Erlang's zlib NIF for SPDY header decompression. Document Filters does not use Erlang/OTP, cowlib, cowboy, or any SPDY protocol implementation, and does not perform unbounded decompression of attacker-controlled streams.)
|
||
| CVE-2026-39804 |
false_positive
(CVE-2026-39804 is a vulnerability in Bandit (mtrudel/bandit), an Elixir HTTP server, not in the zlib C library. The flaw is unbounded decompression in Bandit's WebSocket permessage-deflate handler (Elixir.Bandit.WebSocket.PerMessageDeflate:inflate/2), which calls Erlang's :zlib.inflate/2 without output-size limits. The 'zlib' association exists only because Bandit uses Erlang's zlib NIF internally, but the vulnerability is entirely in Bandit's application-level code. Document Filters does not use Elixir, Erlang/OTP, Bandit, or any WebSocket server. Document Filters uses the C zlib library version 1.3 directly from madler/zlib for compression/decompression with proper bounded buffers.)
|
||
| CVE-2026-35469 |
false_positive
(CVE-2026-35469 is a vulnerability in moby/spdystream (a Go library for SPDY protocol multiplexing), not in the zlib C library. The flaw is unbounded memory allocation in spdystream's Go SPDY/3 frame parser (parseHeaderValueBlock). The 'zlib' association exists only because SPDY headers are zlib-compressed, but the vulnerability is entirely in the Go application code that fails to validate decompressed sizes before allocation. Document Filters does not use Go, does not include spdystream, and does not implement any SPDY protocol handling.)
|
||
| CVE-2026-29035 |
needs_triage
|
||
| CVE-2026-27820 |
not_affected
(CVE-2026-27820 affects the Ruby zlib gem (ruby/zlib), a Ruby-language binding for zlib, not the upstream C zlib library (madler/zlib). The vulnerable function zstream_buffer_ungets is Ruby-specific code that manages Ruby string buffers for Zlib::GzipReader. Document Filters uses the C zlib library version 1.3 directly from madler/zlib and does not include or use any Ruby code, the Ruby zlib gem, or the zstream_buffer_ungets function.)
|
||
| CVE-2026-27171 |
not_affected
(Document Filters never calls crc32_combine64, crc32_combine_gen64, crc32_combine, or crc32_combine_gen. The vulnerable x2nmodp infinite loop can only be triggered by passing a negative length to these combine functions — a code path that Document Filters does not exercise.)
|
||
| CVE-2026-24812 |
needs_triage
|
||
| CVE-2026-24800 |
false_positive
(CVE-2026-24800 affects the furnace project's bundled copy of zlib, not the standalone zlib library. Document Filters does not use furnace; it uses zlib 1.3 directly. The underlying vulnerability (CVE-2022-37434) was a heap buffer overflow in inflate.c when processing gzip headers with large extra fields via inflateGetHeader(). This was fixed in upstream zlib 1.2.13 via commit eff308af425b67093bab25f80f1ae950166bece1. Document Filters uses zlib 1.3 (released August 2023), which includes this fix.)
|
||
| CVE-2026-24799 |
false_positive
(CVE-2026-24799 affects the dlib library's bundled copy of zlib, not the standalone zlib library. Document Filters does not use dlib; it uses zlib 1.3 directly. The underlying vulnerability (CVE-2022-37434) was fixed in upstream zlib via commit eff308af425b67093bab25f80f1ae950166bece1, and zlib 1.3 includes this fix. Our inflate.c contains the patched code with proper bounds checking for gzip header extra fields.)
|
||
| CVE-2026-22184 |
not_affected
(Document Filters only builds zlib core sources and contrib/infback9; the vulnerable contrib/untgz utility is absent from our source tree and never shipped.)
|
||
| CVE-2026-4738 |
not_affected
(CVE-2026-4738 targets unsafe pointer arithmetic (base -= 257; extra -= 257) in inflate_table9() in contrib/infback9/inftree9.c. This is the same vulnerability already fixed in Document Filters via commit 9d560cb1803c4d8e6525a36c994c7af8b4580cff (CVE-2026-24812 fix), which backported upstream zlib commit 6a043145ca6e9c55184013841a67b2fef87e44c0. Our inftree9.c uses the safe 'match' variable pattern and does not contain the vulnerable pointer arithmetic.)
|
||
| CVE-2025-52937 |
not_affected
(The issue is specific to the PointCloudLibrary, which uses a modified version of the ZLib library. This issue does not affect Document Filters.)
|
||
| CVE-2025-5087 |
false_positive
(The issue is specific to the Kaleris NAVIS systems and is a result of improper usage of zlib library, not a vulnerability of the library itself.)
|
||
| CVE-2025-4640 |
not_affected
(Affected code is not utilized by Document Filters.)
|
||
| CVE-2023-53742 |
not_affected
(The issue is related to the Linux kernel and is not a vulnerability of the zlib library itself.)
|
||
| CVE-2023-45853 |
not_affected
(not-exploitable: CVE exists in CLI tool that is not part of zlib library.)
|
||
| CVE-2023-6992 |
false_positive
(Unknown vendors 'cloudflare')
|
||
| CVE-2022-37434 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2018-25032 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2016-9843 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2016-9842 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2016-9841 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2016-9840 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2005-2096 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2005-1849 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2004-0797 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2003-0107 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| CVE-2002-0059 |
not_affected
(1.3 does not match CVE configuration.)
|
||
| qpdf | 8.4.0 | CVE-2024-24246 |
not_affected
(8.4.0 does not match CVE configuration.)
|
| CVE-2022-34503 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2021-36978 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2021-25786 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2018-18020 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2018-9918 |
not_affected
(fixed in qpdf 8.1.0)
|
||
| CVE-2017-18186 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-18185 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-18184 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-18183 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-12595 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-11627 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-11626 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-11625 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-11624 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-9210 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-9209 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2017-9208 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| CVE-2015-9252 |
not_affected
(8.4.0 does not match CVE configuration.)
|
||
| openjpeg | 2.5.3 | CVE-2026-6192 |
needs_triage
|
| CVE-2025-54874 |
resolved
(Patched applied from https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d)
|
||
| CVE-2025-50952 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2024-56827 |
not_affected
(CVE is not marked with a version. Fixed in OpenJPEG 2.5.3)
|
||
| CVE-2024-56826 |
not_affected
(CVE is not marked with a version. Fixed in OpenJPEG 2.5.3)
|
||
| CVE-2023-39329 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2023-39328 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2023-39327 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2022-1122 |
not_affected
(not-exploitable: CVE is in opj2_decompress CLI tool not used by docfilters.)
|
||
| CVE-2021-29338 |
not_affected
(not-exploitable: CVE exists in CLI tool not used by DocFilters.)
|
||
| CVE-2021-3575 |
not_affected
(not-exploitable: CVE is in opj2_decompress CLI tool not used by docfilters.)
|
||
| CVE-2020-27845 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27844 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27843 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27842 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27841 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27824 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27823 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-27814 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-15389 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-8112 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2020-6851 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2019-12973 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2019-6988 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-21010 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-20847 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-20846 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-20845 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-18088 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-16376 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-16375 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-14423 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-7648 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-6616 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-5785 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2018-5727 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-17480 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-17479 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14164 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14152 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14151 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14041 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14040 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-14039 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2017-12982 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-10507 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-10506 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-10505 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-10504 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9675 |
not_affected
(CVE is not marked with a version. Fixed in OpenJPEG 1.5.2)
|
||
| CVE-2016-9581 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9580 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9573 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9572 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9118 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9117 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9116 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9115 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9114 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9113 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-9112 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-8332 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-7445 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-7163 |
not_affected
(CVE is not marked with a version. Fixed in OpenJPEG 1.5.2)
|
||
| CVE-2016-4797 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-4796 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-3183 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-3182 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-1924 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2016-1923 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2015-8871 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2015-1239 |
not_affected
(CVE is not marked with a version. Fixed in OpenJPEG 2.1.0-2+deb8u4)
|
||
| CVE-2014-0158 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-6887 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-6054 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-6053 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-6052 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-6045 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-4290 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-4289 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2013-1447 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2012-3535 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2012-3358 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2012-1499 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| CVE-2009-5030 |
not_affected
(2.5.3 does not match CVE configuration.)
|
||
| tinyxml | 2.6.2 | CVE-2023-34194 |
resolved
(Patched applied from https://salsa.debian.org/debian/tinyxml/-/raw/2366e1f23d059d4c20c43c54176b6bd78d6a83fc/debian/patches/CVE-2023-34194.patch)
|
| CVE-2021-42260 |
resolved
(Patched applied from )
|
||
| oda | 2023.4 | CVE-2023-26495 |
resolved
(Patched applied from https://gitlab.opendesign.com/oda/drawing/-/commit/6bf214a855db885d421ddbd3c4ad8030a07b07ec)
|
| CVE-2023-22670 |
resolved
(Patched applied from https://gitlab.opendesign.com/oda/drawing/-/commit/04ad2b195e9c8f073157f9226f920903ac6addbd)
|
||
| CVE-2023-22669 |
resolved
(Patched applied from https://gitlab.opendesign.com/oda/drawing/-/commit/df4902b8dec5202e61ea8dd7bada4f71444fb0a1)
|
||
| CVE-2023-5180 |
resolved
(Patched applied from https://gitlab.opendesign.com/oda/thirdparty/-/commits/release/23.10/oless/ssrw_c/RootStorage.c)
|
||
| CVE-2023-5179 |
resolved
(Patched applied from https://gitlab.opendesign.com/oda/thirdparty/-/commits/release/23.10/oless/ssrw_c/RootStorage.c)
|
||
| CVE-2022-28809 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2022-28808 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2022-28807 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2022-23095 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44860 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44859 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44422 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44047 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44045 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-44044 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43582 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43391 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43390 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43336 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43280 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43275 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43274 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-43273 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32952 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32950 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32948 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32946 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32944 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32940 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32938 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-32936 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-31784 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25178 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25177 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25176 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25175 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25174 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2021-25173 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2018-18224 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| CVE-2018-18223 |
not_affected
(2023.4 does not match CVE configuration.)
|
||
| pdfium | 5060 |
|
|
| xpdf | 4.05 | CVE-2026-4407 |
needs_triage
|
| CVE-2025-11896 |
needs_triage
|
||
| CVE-2025-3154 |
resolved
(Patched applied from about:blank)
|
||
| CVE-2025-2574 |
not_affected
(The DocumentFilters team manages to patch vulnerabilities independently of upstream security fixes. The issue was resolved without having to wait for an official patch.)
|
||
| CVE-2024-7868 |
not_affected
(The DocumentFilters team manages a set of patches independently of upstream security patches and applies them to Xpdf during updates. In this case, the issue was already mitigated, preventing the conditions leading to the segfault. These fixes were confirmed by executing the vendor-provided proof-of-concept for the CVE.)
|
||
| CVE-2024-7867 |
not_affected
(The issue is in a PSOutputDev (PostScript Output Device) class that is not used by Document Filters. This CVE was found with the 'pdftops' application, which does use this class. Processing the proof-of-concept file for this CVE with Document Filters confirms that Document Filters is not affected.)
|
||
| CVE-2024-7866 |
resolved
(Patched applied from about:blank)
|
||
| CVE-2024-4976 |
not_affected
(The DocumentFilters team manages a set of patches independently of upstream security patches and applies them to Xpdf during updates. In this case, the issue was already mitigated, preventing the conditions leading to the out-of-bounds write. These fixes were confirmed by executing the vendor-provided proof-of-concept for the CVE.)
|
||
| CVE-2024-4568 |
not_affected
(The DocumentFilters team manages a set of patches independently of upstream security patches and applies them to Xpdf during updates. In this case, the issue was already mitigated, preventing the conditions leading to the stack overflow. These fixes were confirmed by executing the vendor-provided proof-of-concept for the CVE.)
|
||
| CVE-2024-4141 |
not_affected
(The DocumentFilters team manages a set of patches independently of upstream security patches and applies them to Xpdf during updates. In this case, the issue was already mitigated, preventing the conditions leading to the out-of-bounds write. These fixes were confirmed by executing the vendor-provided proof-of-concept for the CVE.)
|
||
| CVE-2024-3900 |
resolved
(Patched applied from https://www.xpdfreader.com/download.html)
|
||
| CVE-2024-3248 |
resolved
(Patched applied from https://www.xpdfreader.com/download.html)
|
||
| CVE-2024-3247 |
not_affected
(Document Filters detects and prevents the condition that causes the stack overflow.)
|
||
| CVE-2024-2971 |
resolved
(Patched applied from https://www.xpdfreader.com/download.html)
|
||
| CVE-2023-26930 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2023-3436 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2023-3044 |
not_affected
(Document Filters detects and prevents the condition that causes the div0.)
|
||
| CVE-2023-2664 |
not_affected
(Document Filters has modified xpdf to prevent the infinite recursion and stack overflow error reported for CVE-2023-2664. The POC file fails gracefully.)
|
||
| CVE-2023-2663 |
not_affected
(Document Filters has modified xpdf to prevent the infinite recursion and stack overflow error reported for CVE-2023-2664. The POC file fails gracefully.)
|
||
| CVE-2023-2662 |
not_affected
(The code that causes the div0 is not present in the version of XPdf used by Document Filters)
|
||
| CVE-2022-48545 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-45587 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-45586 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-43295 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-43071 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-41844 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-41843 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-41842 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38928 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38334 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38238 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38237 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38236 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38235 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38234 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38233 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38231 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38230 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38229 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38228 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38227 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38222 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-38171 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-36561 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-33108 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-30775 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-30524 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-27135 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-24107 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2022-24106 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2021-40226 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2021-36493 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2021-30860 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2021-27548 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2020-35376 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2020-25725 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2020-24999 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2020-24996 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-17064 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-16927 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-16115 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-16088 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-15860 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14294 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14293 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14292 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14291 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14290 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14289 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-14288 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13291 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13289 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13288 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13287 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13286 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13283 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13282 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-13281 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-12958 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-12957 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-12515 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-12493 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-12360 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10026 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10025 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10024 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10023 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10022 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10021 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10020 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10019 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-10018 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-9878 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-9877 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-9589 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-9588 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2019-9587 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18651 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18650 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18459 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18458 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18457 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18456 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18455 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-18454 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-16369 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-16368 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-11033 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8107 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8106 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8105 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8104 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8103 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8102 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8101 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-8100 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7455 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7454 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7453 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7452 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7175 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7174 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2018-7173 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2012-2142 |
not_affected
|
||
| CVE-2011-2902 |
not_affected
|
||
| CVE-2010-3704 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2010-3702 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-4035 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-3603 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-1183 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-1182 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-1181 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-1180 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-1179 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0800 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0799 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0195 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0166 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0147 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2009-0146 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2007-5393 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2007-5392 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2007-4352 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2007-3387 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2007-0104 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2006-1244 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2006-0746 |
not_affected
|
||
| CVE-2006-0301 |
not_affected
|
||
| CVE-2005-3628 |
not_affected
|
||
| CVE-2005-3627 |
not_affected
|
||
| CVE-2005-3626 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-3625 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-3624 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-3193 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-3192 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-3191 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-2097 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-0206 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2005-0064 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2004-1125 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2004-0889 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2004-0888 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2003-0434 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2002-1384 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2000-0728 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| CVE-2000-0727 |
not_affected
(4.05 does not match CVE configuration.)
|
||
| safeint | 3.0.28 |
|
|
| bcl | 1.2.11 |
|
|
| gif-h | 0.1 |
|
|
| liberation-fonts | 2.00.5 |
|
|
| droid-fonts | 1 |
|
|
| zxing-cpp | 1.2.0 |
|
|
| gumbo-parser | 0.10.2 |
|
|
| gsl-lite | 0.42.0 |
|