Search CVE reports


Toggle filters

21 – 30 of 32 results


CVE-2017-17521

Low priority
Vulnerable

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted...

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2017-11573

Low priority
Vulnerable

FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2017-11570

Low priority
Vulnerable

FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2017-11577

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11576

Medium priority

Some fixes available 2 of 4

FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11575

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11574

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11572

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11571

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages

CVE-2017-11569

Medium priority

Some fixes available 2 of 4

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages