CVE-2026-102620Low· 3.3▾ SunlitA vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102621Low· 3.3Freedesktop Poppler SplashClip.cc clipToPath integer overflow
CVE-2026-93313Medium· 6.3A vulnerability was found in Freedesktop Poppler 26.07.0
CVE-2026-93311Medium· 4.3A vulnerability was detected in Freedesktop Poppler 26.07.0
CVE-2026-93314Medium· 6.3A vulnerability was determined in Freedesktop Poppler 26.07.0
CVE-2026-93653Medium· 5.5A denial of service flaw was found in Poppler's Splash backend
CVE-2026-93312Medium· 4.3A flaw has been found in Freedesktop Poppler 26.07.0