Search CVE reports


Toggle filters

1 – 10 of 73 results


CVE-2026-40505

Medium priority
Needs evaluation

(MuPDF mutool does not sanitize PDF metadata fields before writing them ...)

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3308

Medium priority
Needs evaluation

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap...

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-3029

Medium priority
Needs evaluation

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

1 affected package

pymupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pymupdf Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-15569

Medium priority
Ignored

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local...

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-25556

Medium priority
Needs evaluation

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer...

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-55780

Medium priority
Needs evaluation

A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does...

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-46206

Medium priority
Fixed

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the...

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-51105

Medium priority

Some fixes available 4 of 7

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-46657

Medium priority

Some fixes available 3 of 4

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

1 affected package

mupdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-24259

Medium priority

Some fixes available 12 of 18

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

2 affected packages

mupdf, freeglut

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mupdf Needs evaluation Fixed Fixed Fixed Fixed
freeglut Needs evaluation Fixed Fixed Fixed Fixed
Show less packages