AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2009-3604

HIGH · CVSS 9.3 EPSS 8.70%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-10-21 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2009-3604
Severity
HIGH
CVSS
9.3
EPSS
8.70%

Original Filing — NVD Description

The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document that triggers a NULL pointer dereference or a heap-based buffer overflow.