Search CVE reports


Toggle filters

1 – 10 of 71 results


CVE-2026-3029

Medium priority
Needs evaluation

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

1 affected package

pymupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pymupdf Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-15569

Medium priority
Ignored

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local...

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-25556

Medium priority
Needs evaluation

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-55780

Medium priority
Needs evaluation

A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does...

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-46206

Medium priority
Fixed

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the...

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-51105

Medium priority

Some fixes available 4 of 7

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-46657

Medium priority

Some fixes available 3 of 4

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-24259

Medium priority

Some fixes available 12 of 16

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

2 affected packages

mupdf, freeglut

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Fixed Fixed Fixed Fixed
freeglut Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-24258

Medium priority

Some fixes available 12 of 16

freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

2 affected packages

mupdf, freeglut

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Fixed Fixed Fixed Fixed
freeglut Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-51107

Medium priority
Needs evaluation

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence...

1 affected package

mupdf

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Ignored Ignored
Show less packages