Vulnerabilities > Redhat > Evince > 0.3

DATE CVE VULNERABILITY TITLE RISK
2011-01-07 CVE-2010-2643 Numeric Errors vulnerability in Redhat Evince
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
network
high complexity
redhat CWE-189
7.6
2011-01-07 CVE-2010-2642 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
network
high complexity
redhat t1lib tug CWE-119
7.6
2011-01-07 CVE-2010-2641 Improper Input Validation vulnerability in Redhat Evince
Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
network
high complexity
redhat CWE-20
7.6
2011-01-07 CVE-2010-2640 Improper Input Validation vulnerability in Redhat Evince
Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.
network
high complexity
redhat CWE-20
7.6