Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:freetype:freetype:2.0.1:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2012-5670 |
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negative value. Published: January 24, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-5669 |
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read. Published: January 24, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-5668 |
FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_free_font function. Published: January 24, 2013; 4:55:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-1144 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1143 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2012-1142 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1141 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1140 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1139 |
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1138 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1137 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1136 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1135 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1134 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1133 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1132 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1131 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1130 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1129 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2012-1128 |
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font. Published: April 25, 2012; 6:10:18 AM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |