CVE-2009-0165
UnknownEPSS 3.59%
Last modified
CVE-2009-0165 is a vulnerability of currently unknown severity. Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn.". EPSS estimates a 3.59% chance of exploitation in the next 30 days.
Description
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foolabs | Xpdf | 0.5a |
| Foolabs | Xpdf | 0.7a |
| Foolabs | Xpdf | 0.91a |
| Foolabs | Xpdf | 0.91b |
| Foolabs | Xpdf | 0.91c |
| Foolabs | Xpdf | 0.92a |
| Foolabs | Xpdf | 0.92b |
| Foolabs | Xpdf | 0.92c |
| Foolabs | Xpdf | 0.92d |
| Foolabs | Xpdf | 0.92e |
| Foolabs | Xpdf | 0.93a |
| Foolabs | Xpdf | 0.93b |
| Foolabs | Xpdf | 0.93c |
| Foolabs | Xpdf | 1.00a |
| Foolabs | Xpdf | 3.0.1 |
| Glyphandcog | Xpdfreader | <= 3.02 |
| Glyphandcog | Xpdfreader | 0.2 |
| Glyphandcog | Xpdfreader | 0.3 |
| Glyphandcog | Xpdfreader | 0.4 |
| Glyphandcog | Xpdfreader | 0.5 |
| Glyphandcog | Xpdfreader | 0.6 |
| Glyphandcog | Xpdfreader | 0.7 |
| Glyphandcog | Xpdfreader | 0.80 |
| Glyphandcog | Xpdfreader | 0.90 |
| Glyphandcog | Xpdfreader | 0.91 |
| Glyphandcog | Xpdfreader | 0.92 |
| Glyphandcog | Xpdfreader | 0.93 |
| Glyphandcog | Xpdfreader | 1.00 |
| Glyphandcog | Xpdfreader | 1.01 |
| Glyphandcog | Xpdfreader | 2.00 |
| Glyphandcog | Xpdfreader | 2.01 |
| Glyphandcog | Xpdfreader | 2.02 |
| Glyphandcog | Xpdfreader | 2.03 |
| Glyphandcog | Xpdfreader | 3.00 |
| Glyphandcog | Xpdfreader | 3.01 |
References
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0165?
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."
How severe is CVE-2009-0165?
Severity scoring for CVE-2009-0165 is pending analysis. The EPSS model estimates a 3.59% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0165?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0159Stack-based buffer overflow in the cookedprint function in n…
- CVE-2009-0160QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before …
- CVE-2009-0161The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 bef…
- CVE-2009-0162Cross-site scripting (XSS) vulnerability in Safari before 3.…
- CVE-2009-0163Integer overflow in the TIFF image decoding routines in CUPS…
- CVE-2009-0164The web interface for CUPS before 1.3.10 does not validate t…
- CVE-2009-0166The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 an…
- CVE-2009-0167Unspecified vulnerability in lpadmin in Sun Solaris 10 and O…
- CVE-2009-0168Unspecified vulnerability in ppdmgr in Sun Solaris 10 and Op…
- CVE-2009-0169Sun Java System Access Manager 7.1 allows remote authenticat…
- CVE-2009-0170Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1…
- CVE-2009-0171The Sun SPARC Enterprise M4000 and M5000 Server, within a ce…
Are you affected by CVE-2009-0165?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
