Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-23 | CVE-2017-11575 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c. | 7.8 |
2017-07-23 | CVE-2017-11574 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11573 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11572 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11571 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11570 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11569 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11568 | Out-of-bounds Read vulnerability in Fontforge 20161012 FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file. | 7.8 |
2017-07-23 | CVE-2017-11565 | Unspecified vulnerability in Debian TOR 0.2.9.111 debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leveraging the silent loss of this protection mechanism. | 7.5 |
2017-07-23 | CVE-2017-11556 | Uncontrolled Recursion vulnerability in Libsass 3.4.5 There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. | 7.5 |