Back to Database
Status published
Medium
CVE-2009-0755
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers...
Vulnerability Description
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0755
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/33749
- http://www.debian.org/security/2009/dsa-1941
- http://lists.freedesktop.org/archives/poppler/2009-January/004406.html
- http://secunia.com/advisories/33853
- http://www.openwall.com/lists/oss-security/2009/02/19/2
- http://secunia.com/advisories/37114
- http://www.openwall.com/lists/oss-security/2009/02/13/1
- http://wiki.rpath.com/Advisories:rPSA-2009-0059
- http://bugs.freedesktop.org/show_bug.cgi?id=19790
- http://secunia.com/advisories/35685
- http://www.ubuntu.com/usn/USN-850-1
- http://www.securityfocus.com/archive/1/502761/100/0/threaded
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
More from poppler
View All →CVE-2025-52886
Poppler Use After Free Vulnerability
Medium
5.5
CVE-2025-52885
GHSL-2025-042: Poppler has Use-After-Free
Medium
6.1
CVE-2012-2142
The error function in Error.cc in poppler before 0.21.4 allows...
High
7.8
CVE-2010-4654
poppler before 0.16.3 has malformed commands that may cause corruption...
High
7.8
CVE-2010-4653
An integer overflow condition in poppler before 0.16.3 can occur...
Medium
6.5
Affected Vendor
poppler
View all reports →Affected Software
poppler
Vulnerable Versions:
0, 0.1, 0.1.1, 0.1.2, 0.2.0, 0.3.0, 0.3.1, 0.3.2, 0.3.3, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.9, 0.5.90, 0.5.91, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.8.4, 0.10.1, 0.10.2
Timeline
Official Publish:
March 3rd, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.