CVE-2014-9664
- EPSS 1.15%
- Published 08.02.2015 11:59:26
- Last modified 12.04.2025 10:46:40
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related ...
CVE-2014-9663
- EPSS 2.61%
- Published 08.02.2015 11:59:25
- Last modified 12.04.2025 10:46:40
The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly ...
CVE-2014-9661
- EPSS 4.95%
- Published 08.02.2015 11:59:23
- Last modified 12.04.2025 10:46:40
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a craf...
CVE-2014-9660
- EPSS 4.85%
- Published 08.02.2015 11:59:22
- Last modified 12.04.2025 10:46:40
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact...
CVE-2014-9658
- EPSS 1.52%
- Published 08.02.2015 11:59:20
- Last modified 12.04.2025 10:46:40
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a craft...
CVE-2014-9657
- EPSS 1.52%
- Published 08.02.2015 11:59:19
- Last modified 12.04.2025 10:46:40
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a cr...
CVE-2015-0236
- EPSS 0.56%
- Published 29.01.2015 15:59:00
- Last modified 12.04.2025 10:46:40
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interf...
- EPSS 0.4%
- Published 21.01.2015 19:59:17
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
CVE-2014-7300
- EPSS 0.04%
- Published 25.12.2014 21:59:02
- Last modified 12.04.2025 10:46:40
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstati...
CVE-2014-8136
- EPSS 0.13%
- Published 19.12.2014 15:59:10
- Last modified 12.04.2025 10:46:40
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.