← Vulnerability feed

Vulnerability record · CVE-2009-0165 · published 23 April 2009

CVE-2009-0165: Foolabs xpdf vulnerability

FFoolabs · Xpdf

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."

10.0 CVSS 2.0 High EPSS 3.6% · top 11.0% CWE-189 · CWE-189
10.0CVSS 2.0 base score
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
48References
16 Jun 2026Last modified by NVD

Description

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=263028 Patch
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://secunia.com/advisories/34852
http://secunia.com/advisories/34959
http://secunia.com/advisories/34991
http://secunia.com/advisories/35037
http://secunia.com/advisories/35065
http://secunia.com/advisories/35074
http://secunia.com/advisories/35685
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
http://support.apple.com/kb/HT3549
http://support.apple.com/kb/HT3639
http://www.debian.org/security/2009/dsa-1790
http://www.debian.org/security/2009/dsa-1793
http://www.mandriva.com/security/advisories?name=MDVSA-2009:101
http://www.securityfocus.com/bid/34568
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2009/1297
http://www.vupen.com/english/advisories/2009/1621
https://exchange.xforce.ibmcloud.com/vulnerabilities/50377
http://bugs.gentoo.org/show_bug.cgi?id=263028 Patch
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://secunia.com/advisories/34852
http://secunia.com/advisories/34959
http://secunia.com/advisories/34991
http://secunia.com/advisories/35037
http://secunia.com/advisories/35065
http://secunia.com/advisories/35074
http://secunia.com/advisories/35685
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.578477
http://support.apple.com/kb/HT3549
http://support.apple.com/kb/HT3639

Track CVE-2009-0165 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3603Foolabs xpdf vulnerabilityInteger overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to exec…EPSS 8.6%9.3CVE-2009-3604Foolabs xpdf vulnerabilityThe Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not prope…EPSS 8.7%9.3CVE-2009-3606Foolabs xpdf vulnerabilityInteger overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote a…EPSS 8.6%9.3CVE-2009-3608Foolabs xpdf vulnerabilityInteger overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegrap…EPSS 10%7.8CVE-2022-24106Glyphandcog xpdfreader integer overflow vulnerabilityIn Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leadin…EPSS 0.31%7.8CVE-2022-24107Glyphandcog xpdfreader integer overflow vulnerabilityXpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.EPSS 0.31%7.8CVE-2019-16115Glyphandcog xpdfreader out-of-bounds read vulnerabilityIn Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor.…EPSS 1.1%7.8CVE-2019-14288Glyphandcog xpdfreader integer overflow vulnerabilityAn issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per li…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2009-0165), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.