Back to Database
Status published
Medium
CVE-2018-18897
An issue was discovered in Poppler 0.71.0. There is a...
Vulnerability Description
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18897
Credits & Attribution
No credits recorded in the NVD database.
References
More from freedesktop
View All →CVE-2025-52968
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict...
Low
2.7
CVE-2025-43903
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1...
Medium
4.3
CVE-2025-43718
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and...
Low
2.9
CVE-2025-32365
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds...
Medium
4
CVE-2025-32364
A floating-point exception in the PSStack::roll function of Poppler before...
Medium
4
Affected Vendor
freedesktop
View all reports →Affected Software
poppler, debian linux, ubuntu linux, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation
Vulnerable Versions:
0.71.0, 10.0, 16.04, 18.04, 18.10, 19.04, 8.0, 7.0, 8.1, 8.2, 8.4, 8.6
Timeline
Official Publish:
November 2nd, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.