4.3

CVE-2011-1554

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

Data is provided by the National Vulnerability Database (NVD)
T1libT1lib Version <= 5.1.2
T1libT1lib Version0.1 Updatealpha
T1libT1lib Version0.2 Updatebeta
T1libT1lib Version0.3 Updatebeta
T1libT1lib Version0.4 Updatebeta
T1libT1lib Version0.5 Updatebeta
T1libT1lib Version0.6 Updatebeta
T1libT1lib Version0.7 Updatebeta
T1libT1lib Version0.8 Updatebeta
T1libT1lib Version0.9
T1libT1lib Version0.9.1
T1libT1lib Version0.9.2
T1libT1lib Version1.0
T1libT1lib Version1.0.1
T1libT1lib Version1.1.0
T1libT1lib Version1.1.1
T1libT1lib Version1.2
T1libT1lib Version1.3
T1libT1lib Version1.3.1
T1libT1lib Version5.0.0
T1libT1lib Version5.0.1
T1libT1lib Version5.0.2
T1libT1lib Version5.1.0
T1libT1lib Version5.1.1
FoolabsXpdf Version0.5a
FoolabsXpdf Version0.7a
FoolabsXpdf Version0.91a
FoolabsXpdf Version0.91b
FoolabsXpdf Version0.91c
FoolabsXpdf Version0.92a
FoolabsXpdf Version0.92b
FoolabsXpdf Version0.92c
FoolabsXpdf Version0.92d
FoolabsXpdf Version0.92e
FoolabsXpdf Version0.93a
FoolabsXpdf Version0.93b
FoolabsXpdf Version0.93c
FoolabsXpdf Version1.00a
FoolabsXpdf Version3.0.1
FoolabsXpdf Version3.02pl1
FoolabsXpdf Version3.02pl2
FoolabsXpdf Version3.02pl3
FoolabsXpdf Version3.02pl4
GlyphandcogXpdfreader Version <= 3.02
GlyphandcogXpdfreader Version0.2
GlyphandcogXpdfreader Version0.3
GlyphandcogXpdfreader Version0.4
GlyphandcogXpdfreader Version0.5
GlyphandcogXpdfreader Version0.6
GlyphandcogXpdfreader Version0.7
GlyphandcogXpdfreader Version0.80
GlyphandcogXpdfreader Version0.90
GlyphandcogXpdfreader Version0.91
GlyphandcogXpdfreader Version0.92
GlyphandcogXpdfreader Version0.93
GlyphandcogXpdfreader Version1.00
GlyphandcogXpdfreader Version1.01
GlyphandcogXpdfreader Version2.00
GlyphandcogXpdfreader Version2.01
GlyphandcogXpdfreader Version2.02
GlyphandcogXpdfreader Version2.03
GlyphandcogXpdfreader Version3.00
GlyphandcogXpdfreader Version3.01
GlyphandcogXpdfreader Version3.02
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.58% 0.902
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P