← Vulnerability feed

Vulnerability record · CVE-2005-3192 · published 8 December 2005

CVE-2005-3192: Xpdf memory buffer overflow vulnerability

Xpdf · Xpdf

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

7.5 CVSS 2.0 High EPSS 6.1% · top 6.8% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
224References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.01pl1.patch Patch
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.20/SCOSA-2006.20.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.21/SCOSA-2006.21.txt
ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=342289
http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html
http://rhn.redhat.com/errata/RHSA-2005-868.html Vendor Advisory
http://scary.beasts.org/security/CESA-2005-003.txt
http://secunia.com/advisories/17897/ PatchVendor Advisory
http://secunia.com/advisories/17908 Vendor Advisory
http://secunia.com/advisories/17912 Vendor Advisory
http://secunia.com/advisories/17916 Vendor Advisory
http://secunia.com/advisories/17920 Vendor Advisory
http://secunia.com/advisories/17921 Vendor Advisory
http://secunia.com/advisories/17926 Vendor Advisory
http://secunia.com/advisories/17929 Vendor Advisory
http://secunia.com/advisories/17940 Vendor Advisory
http://secunia.com/advisories/17955
http://secunia.com/advisories/17976 Vendor Advisory
http://secunia.com/advisories/18009 Vendor Advisory
http://secunia.com/advisories/18055 Vendor Advisory
http://secunia.com/advisories/18061 Vendor Advisory
http://secunia.com/advisories/18189 Vendor Advisory
http://secunia.com/advisories/18191 Vendor Advisory
http://secunia.com/advisories/18192 Vendor Advisory
http://secunia.com/advisories/18303
http://secunia.com/advisories/18313 Vendor Advisory
http://secunia.com/advisories/18336 Vendor Advisory
http://secunia.com/advisories/18349 Vendor Advisory
http://secunia.com/advisories/18380
http://secunia.com/advisories/18385
http://secunia.com/advisories/18387 Vendor Advisory
http://secunia.com/advisories/18389 Vendor Advisory
http://secunia.com/advisories/18398
http://secunia.com/advisories/18407
http://secunia.com/advisories/18416 Vendor Advisory
http://secunia.com/advisories/18428

Track CVE-2005-3192 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%9.3CVE-2009-4035Gnome gpdf code injection vulnerabilityThe FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…EPSS 3.8%9.3CVE-2007-5392Xpdf memory buffer overflow vulnerabilityInteger overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF…EPSS 6.4%9.3CVE-2007-5393Xpdf memory buffer overflow vulnerabilityHeap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code…EPSS 6.4%9.3CVE-2004-1125Easy software products cups improper input validation vulnerabilityBuffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3…EPSS 6.6%7.6CVE-2007-4352Xpdf vulnerabilityArray index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, …EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2005-3192), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.