← Vulnerability feed

Vulnerability record · CVE-2009-4035 · published 21 December 2009

CVE-2009-4035: Gnome gpdf code injection vulnerability

Gnome · Gpdf

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

9.3 CVSS 2.0 High EPSS 3.8% · top 10.4% CWE-94 · Code injection
9.3CVSS 2.0 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0
http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81a
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html
http://secunia.com/advisories/37641 Vendor Advisory
http://secunia.com/advisories/37781 Vendor Advisory
http://secunia.com/advisories/37787 Vendor Advisory
http://secunia.com/advisories/37793 Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-1680.html
http://www.redhat.com/support/errata/RHSA-2009-1681.html
http://www.redhat.com/support/errata/RHSA-2009-1682.html
http://www.securityfocus.com/bid/37350
http://www.securitytracker.com/id?1023356
http://www.vupen.com/english/advisories/2009/3555 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=541614
https://exchange.xforce.ibmcloud.com/vulnerabilities/54831
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10996
http://cgit.freedesktop.org/poppler/poppler/diff/fofi/FoFiType1.cc?id=4b4fc5c0
http://cgit.freedesktop.org/poppler/poppler/tree/fofi/FoFiType1.cc?id=4b4fc5c017bf147c9069bbce32fc14467bd2a81a
http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html
http://secunia.com/advisories/37641 Vendor Advisory
http://secunia.com/advisories/37781 Vendor Advisory
http://secunia.com/advisories/37787 Vendor Advisory
http://secunia.com/advisories/37793 Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-1680.html
http://www.redhat.com/support/errata/RHSA-2009-1681.html
http://www.redhat.com/support/errata/RHSA-2009-1682.html
http://www.securityfocus.com/bid/37350
http://www.securitytracker.com/id?1023356
http://www.vupen.com/english/advisories/2009/3555 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=541614
https://exchange.xforce.ibmcloud.com/vulnerabilities/54831
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10996

Track CVE-2009-4035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%9.3CVE-2007-5392Xpdf memory buffer overflow vulnerabilityInteger overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF…EPSS 6.4%9.3CVE-2007-5393Xpdf memory buffer overflow vulnerabilityHeap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code…EPSS 6.4%9.3CVE-2004-1125Easy software products cups improper input validation vulnerabilityBuffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3…EPSS 6.6%7.6CVE-2007-4352Xpdf vulnerabilityArray index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, …EPSS 7.0%7.6CVE-2006-1244Gnome gpdf vulnerabilityUnspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2009-4035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.