Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2009-1144 Details
Description
Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| foolabs xpdf | 0.5a 0.7a 0.91a 0.91b 0.91c 0.92a 0.92b 0.92c 0.92d 0.92e 0.93a 0.93b 0.93c 1.00a |
CPE
Remediation
| |
| glyphandcog xpdfreader | <= 3.02 0.2 0.3 0.4 0.5 0.6 0.7 0.80 0.90 0.91 0.93 1.00 1.01 2.00 2.01 2.02 2.03 3.00 |
CPE
Remediation
| |
| gentoo gentoo linux | All versions |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Mar 6, 2019 | CPE Deprecation Remap | [email protected] |
| Apr 9, 2009 | Initial Analysis | [email protected] |