CVE-2008-2950
CVE-2008-2950 is a high-severity vulnerability in Poppler with a CVSS 2.0 base score of 7.5. Its EPSS exploit-prediction score of 15% places it in the 97th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 15% (97th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Poppler
- Published:
- Last modified:
Description
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
Frequently asked questions
- What is CVE-2008-2950?
- The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.
- How severe is CVE-2008-2950?
- CVE-2008-2950 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2008-2950 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 15% (97th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2008-2950?
- CVE-2008-2950 affects Poppler. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2008-2950?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2008-2950 published?
- CVE-2008-2950 was published on 2008-07-07 and last updated on 2026-06-16.
References
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00006.html
- http://secunia.com/advisories/30963
- http://secunia.com/advisories/31002
- http://secunia.com/advisories/31167
- http://secunia.com/advisories/31267
- http://secunia.com/advisories/31405
- http://security.gentoo.org/glsa/glsa-200807-04.xml
- http://securityreason.com/securityalert/3977
- http://wiki.rpath.com/Advisories:rPSA-2008-0223
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:146
- http://www.ocert.org/advisories/ocert-2008-007.html
- http://www.securityfocus.com/archive/1/493980/100/0/threaded
- http://www.securityfocus.com/archive/1/494142/100/0/threaded
- http://www.securityfocus.com/bid/30107
- http://www.securitytracker.com/id?1020435
- http://www.ubuntu.com/usn/usn-631-1
- http://www.vupen.com/english/advisories/2008/2024/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43619
- https://www.exploit-db.com/exploits/6032
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00161.html
Affected products (1)
- cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:*
More vulnerabilities in Poppler
- CVE-2005-3625 — Critical (CVSS 10.0): Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows…
- CVE-2009-3608 — Critical (CVSS 9.3): Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before…
- CVE-2009-3607 — Critical (CVSS 9.3): Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows…
- CVE-2009-3606 — Critical (CVSS 9.3): Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in…
- CVE-2009-3604 — Critical (CVSS 9.3): The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and…
- CVE-2009-3603 — Critical (CVSS 9.3): Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might…
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-105857 — Critical (CVSS 10.0): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions…
- CVE-2026-55107 — Critical (CVSS 10.0): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted…
- CVE-2026-96349 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
- CVE-2026-102425 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa…
- CVE-2026-89275 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…
- CVE-2026-84412 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…