← Vulnerability feed

Vulnerability record · CVE-2007-0104 · published 9 January 2007

CVE-2007-0104: Xpdf improper input validation vulnerability

Xpdf · Xpdf

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

6.8 CVSS 2.0 Medium EPSS 6.1% · top 6.9% CWE-20 · Improper input validation
6.8CVSS 2.0 base score
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
68References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=305214
http://projects.info-pull.com/moab/MOAB-06-01-2007.html
http://secunia.com/advisories/23791
http://secunia.com/advisories/23799 Vendor Advisory
http://secunia.com/advisories/23808 Vendor Advisory
http://secunia.com/advisories/23813 Vendor Advisory
http://secunia.com/advisories/23815 Vendor Advisory
http://secunia.com/advisories/23839 Vendor Advisory
http://secunia.com/advisories/23844 Vendor Advisory
http://secunia.com/advisories/23876 Vendor Advisory
http://secunia.com/advisories/24204 Vendor Advisory
http://secunia.com/advisories/24479 Vendor Advisory
http://securitytracker.com/id?1017514
http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html
http://www.kde.org/info/security/advisory-20070115-1.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2007:018
http://www.mandriva.com/security/advisories?name=MDKSA-2007:019
http://www.mandriva.com/security/advisories?name=MDKSA-2007:020
http://www.mandriva.com/security/advisories?name=MDKSA-2007:021
http://www.mandriva.com/security/advisories?name=MDKSA-2007:022
http://www.mandriva.com/security/advisories?name=MDKSA-2007:024
http://www.novell.com/linux/security/advisories/2007_3_sr.html
http://www.securityfocus.com/archive/1/457055/100/0/threaded
http://www.securityfocus.com/bid/21910 Exploit
http://www.securitytracker.com/id?1017749
http://www.ubuntu.com/usn/usn-410-1
http://www.ubuntu.com/usn/usn-410-2
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0203 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0212 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0244 Vendor Advisory
http://www.vupen.com/english/advisories/2007/0930 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/31364
https://issues.rpath.com/browse/RPL-964
http://docs.info.apple.com/article.html?artnum=305214
http://projects.info-pull.com/moab/MOAB-06-01-2007.html
http://secunia.com/advisories/23791
http://secunia.com/advisories/23799 Vendor Advisory
http://secunia.com/advisories/23808 Vendor Advisory
http://secunia.com/advisories/23813 Vendor Advisory

Track CVE-2007-0104 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2005-0011Kde vulnerabilityMultiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (IND…EPSS 4.9%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%10.0CVE-2003-0690Kde vulnerabilityKDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by tri…EPSS 3.1%9.3CVE-2009-4035Gnome gpdf code injection vulnerabilityThe FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, d…EPSS 3.8%9.3CVE-2008-1670Kde memory buffer overflow vulnerabilityHeap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to …EPSS 4.8%9.3CVE-2007-5392Xpdf memory buffer overflow vulnerabilityInteger overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF…EPSS 6.4%

Source: NIST National Vulnerability Database (record CVE-2007-0104), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.