Show filters
91 Total Results
Displaying 51-60 of 91
Sort by:
Attacker Value
Unknown

CVE-2014-9669

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
0
Attacker Value
Unknown

CVE-2014-9672

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
0
Attacker Value
Unknown

CVE-2014-9664

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
0
Attacker Value
Unknown

CVE-2014-9658

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
0
Attacker Value
Unknown

CVE-2014-9657

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
0
Attacker Value
Unknown

CVE-2014-9660

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
0
Attacker Value
Unknown

CVE-2014-9670

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
0
Attacker Value
Unknown

CVE-2015-1380

Disclosure Date: February 03, 2015 (last updated October 05, 2023)
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
0
Attacker Value
Unknown

CVE-2015-1038

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
0
Attacker Value
Unknown

CVE-2015-1196

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
0