CVE-2013-1789: Freedesktop Poppler

Medium severity, CVSS 4.3. EPSS: 2.4% chance of exploitation in the next 30 days.

splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions.

Affected products

Published 2013-04-09. Last modified 2026-06-16.