CVE-2010-2226
- EPSS 0.08%
- Veröffentlicht 03.09.2010 20:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file i...
CVE-2010-2531
- EPSS 5.71%
- Veröffentlicht 20.08.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the a...
CVE-2010-2498
- EPSS 2.65%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The psh_glyph_find_strong_points function in pshinter/pshalgo.c in FreeType before 2.4.0 does not properly implement hinting masks, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly ...
CVE-2010-2499
- EPSS 3.38%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with a...
CVE-2010-2500
- EPSS 2.65%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CVE-2010-2519
- EPSS 4.52%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a PO...
CVE-2010-2520
- EPSS 3.15%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the Ins_IUP function in truetype/ttinterp.c in FreeType before 2.4.0, when TrueType bytecode support is enabled, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code...
CVE-2010-2527
- EPSS 2.33%
- Veröffentlicht 19.08.2010 18:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CVE-2010-2497
- EPSS 2.09%
- Veröffentlicht 19.08.2010 18:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CVE-2010-2547
- EPSS 15.1%
- Veröffentlicht 05.08.2010 18:17:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, ...