T1lib

T1lib

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.78%
  • Veröffentlicht 19.11.2012 12:10:49
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and po...

  • EPSS 1.89%
  • Veröffentlicht 19.11.2012 12:10:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI...

  • EPSS 22.37%
  • Veröffentlicht 31.03.2011 23:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a dif...

  • EPSS 4.95%
  • Veröffentlicht 31.03.2011 23:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that trig...

  • EPSS 6.58%
  • Veröffentlicht 31.03.2011 23:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an inva...

  • EPSS 31.19%
  • Veröffentlicht 31.03.2011 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF docume...

  • EPSS 12.56%
  • Veröffentlicht 07.01.2011 19:00:17
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execut...

Exploit
  • EPSS 24.85%
  • Veröffentlicht 27.07.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloa...