MEDIUM

CVE-2026-93314

2026-09-18 CVSS v3.1
CVSS
6.3

Description

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called ed2a5538cf0a8d3ff908191eda9b73f91a5f952a. It is advisable to implement a patch to correct this issue.

Weakness (CWE)

CWE-189 Numeric Errors
CWE-190 Integer Overflow

EPSS Score

0.25%
Probability of exploitation in next 30 days
16.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE