Show filters
106 Total Results
Displaying 21-30 of 106
Sort by:
Attacker Value
Unknown
CVE-2014-9657
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
0
Attacker Value
Unknown
CVE-2014-9660
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
0
Attacker Value
Unknown
CVE-2014-9670
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
0
Attacker Value
Unknown
CVE-2015-1380
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
0
Attacker Value
Unknown
CVE-2015-1196
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
0
Attacker Value
Unknown
CVE-2014-9496
Disclosure Date: January 16, 2015 (last updated October 05, 2023)
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2014-9601
Disclosure Date: January 16, 2015 (last updated October 05, 2023)
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
0
Attacker Value
Unknown
CVE-2015-0564
Disclosure Date: January 10, 2015 (last updated October 05, 2023)
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
0
Attacker Value
Unknown
CVE-2015-0561
Disclosure Date: January 10, 2015 (last updated October 05, 2023)
asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2014-5353
Disclosure Date: December 16, 2014 (last updated October 05, 2023)
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.
0