Show filters
133 Total Results
Displaying 81-90 of 133
Sort by:
Attacker Value
Unknown
CVE-2010-2527
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2807
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2498
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted font file that triggers an invalid free operation.
0
Attacker Value
Unknown
CVE-2010-2500
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2520
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2519
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font file.
0
Attacker Value
Unknown
CVE-2010-2541
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2805
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2010-2806
Disclosure Date: August 19, 2010 (last updated October 04, 2023)
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2010-0834
Disclosure Date: August 10, 2010 (last updated October 04, 2023)
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
0