Search Results (Refine Search)
- CPE Product Version: cpe:/a:freetype:freetype:2.1.8:rc1
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2012-1128 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1127 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font. Published: April 25, 2012; 6:10:17 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1126 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font. Published: April 25, 2012; 6:10:17 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
CVE-2010-3311 |
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797. Published: January 07, 2011; 6:00:18 PM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-3814 |
Heap-based buffer overflow in the Ins_SHZ function in ttinterp.c in FreeType 2.4.3 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SHZ bytecode instruction, related to TrueType opcodes, as demonstrated by a PDF document with a crafted embedded font. Published: November 26, 2010; 3:00:02 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |