Show filters
94 Total Results
Displaying 41-50 of 94
Sort by:
Attacker Value
Unknown
CVE-2014-9670
Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
0
Attacker Value
Unknown
CVE-2014-2241
Disclosure Date: March 18, 2014 (last updated October 05, 2023)
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
0
Attacker Value
Unknown
CVE-2014-2240
Disclosure Date: March 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.
0
Attacker Value
Unknown
CVE-2012-5670
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negative value.
0
Attacker Value
Unknown
CVE-2012-5669
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2012-5668
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_free_font function.
0
Attacker Value
Unknown
CVE-2012-1132
Disclosure Date: April 25, 2012 (last updated October 04, 2023)
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
0
Attacker Value
Unknown
CVE-2012-1141
Disclosure Date: April 25, 2012 (last updated October 04, 2023)
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.
0
Attacker Value
Unknown
CVE-2012-1136
Disclosure Date: April 25, 2012 (last updated October 04, 2023)
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.
0
Attacker Value
Unknown
CVE-2012-1126
Disclosure Date: April 25, 2012 (last updated October 04, 2023)
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.
0