← Vulnerability feed

Vulnerability record · CVE-2005-3627 · published 31 December 2005

CVE-2005-3627: Xpdf memory buffer overflow vulnerability

Xpdf · Xpdf

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

7.5 CVSS 2.0 High EPSS 5.5% · top 7.5% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
172References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt
ftp://patches.sgi.com/support/free/security/advisories/20051201-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U
http://lists.suse.com/archive/suse-security-announce/2006-Jan/0001.html PatchVendor Advisory
http://rhn.redhat.com/errata/RHSA-2006-0177.html PatchVendor Advisory
http://scary.beasts.org/security/CESA-2005-003.txt ExploitVendor Advisory
http://secunia.com/advisories/18147
http://secunia.com/advisories/18303 PatchVendor Advisory
http://secunia.com/advisories/18312 PatchVendor Advisory
http://secunia.com/advisories/18313 PatchVendor Advisory
http://secunia.com/advisories/18329 Vendor Advisory
http://secunia.com/advisories/18332 Vendor Advisory
http://secunia.com/advisories/18334 PatchVendor Advisory
http://secunia.com/advisories/18335 PatchVendor Advisory
http://secunia.com/advisories/18338 PatchVendor Advisory
http://secunia.com/advisories/18349 PatchVendor Advisory
http://secunia.com/advisories/18373
http://secunia.com/advisories/18375 Vendor Advisory
http://secunia.com/advisories/18380
http://secunia.com/advisories/18385 PatchVendor Advisory
http://secunia.com/advisories/18387 PatchVendor Advisory
http://secunia.com/advisories/18389 PatchVendor Advisory
http://secunia.com/advisories/18398 PatchVendor Advisory
http://secunia.com/advisories/18407 PatchVendor Advisory
http://secunia.com/advisories/18414
http://secunia.com/advisories/18416 PatchVendor Advisory
http://secunia.com/advisories/18423 PatchVendor Advisory
http://secunia.com/advisories/18425
http://secunia.com/advisories/18428
http://secunia.com/advisories/18436
http://secunia.com/advisories/18448 PatchVendor Advisory
http://secunia.com/advisories/18463
http://secunia.com/advisories/18517 PatchVendor Advisory
http://secunia.com/advisories/18534 PatchVendor Advisory
http://secunia.com/advisories/18554 PatchVendor Advisory
http://secunia.com/advisories/18582 PatchVendor Advisory
http://secunia.com/advisories/18642 Vendor Advisory
http://secunia.com/advisories/18644 Vendor Advisory
http://secunia.com/advisories/18674 Vendor Advisory

Track CVE-2005-3627 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%9.3CVE-2009-4035Gnome gpdf code injection vulnerabilityThe FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…EPSS 3.8%9.3CVE-2007-5392Xpdf memory buffer overflow vulnerabilityInteger overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF…EPSS 6.4%9.3CVE-2007-5393Xpdf memory buffer overflow vulnerabilityHeap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code…EPSS 6.4%9.3CVE-2004-1125Easy software products cups improper input validation vulnerabilityBuffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3…EPSS 6.6%7.6CVE-2007-4352Xpdf vulnerabilityArray index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, …EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2005-3627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.