Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-24 CVE-2017-11587 Path Traversal vulnerability in Cisco Residential Gateway Firmware Ddr2200Bnaannexafccv00.00.03.45.4E/Ddr2201V1Naannexafccv00.00.03.28.3
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.
network
low complexity
cisco CWE-22
7.5
2017-07-23 CVE-2017-11577 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11575 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11574 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-119
7.8
2017-07-23 CVE-2017-11573 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11572 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11571 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-119
7.8
2017-07-23 CVE-2017-11570 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11569 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8
2017-07-23 CVE-2017-11568 Out-of-bounds Read vulnerability in Fontforge 20161012
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.
local
low complexity
fontforge CWE-125
7.8