Show filters
156 Total Results
Displaying 141-150 of 156
Sort by:
Attacker Value
Unknown
CVE-2014-9664
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
0
Attacker Value
Unknown
CVE-2014-9657
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
0
Attacker Value
Unknown
CVE-2014-9675
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
0
Attacker Value
Unknown
CVE-2014-9673
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
0
Attacker Value
Unknown
CVE-2014-9660
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
0
Attacker Value
Unknown
CVE-2014-9661
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
0
Attacker Value
Unknown
CVE-2014-9670
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
0
Attacker Value
Unknown
CVE-2014-8136
Disclosure Date: December 19, 2014 (last updated October 05, 2023)
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-0553
Disclosure Date: September 10, 2014 (last updated October 05, 2023)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-1484
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
0