Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,419 CVEs tagged to vendor fedoraproject472 Critical, 2,345 High, 2,338 Medium, 264 Low, 0 Unrated.

CVE-2014-9664

Published Feb 8, 2015

FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or pos…

CVSS 6.8 · Medium

CVE-2014-9663

Published Feb 8, 2015

The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote a…

CVSS 7.5 · High

CVE-2014-9661

Published Feb 8, 2015

type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of servic…

CVSS 7.5 · High

CVE-2014-9660

Published Feb 8, 2015

The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of servi…

CVSS 7.5 · High

CVE-2014-9658

Published Feb 8, 2015

The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (ou…

CVSS 7.5 · High

CVE-2014-9657

Published Feb 8, 2015

The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service…

CVSS 7.5 · High

CVE-2015-1463

Published Feb 3, 2015

ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1461

Published Feb 3, 2015

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8630

Published Feb 1, 2015

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by lever…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,051-5,075 of 5,419 CVEsPage 203 of 217