T1lib
t1lib
8 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a de...Show more |
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly ex...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Typ...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1...Show more |
3Foolabs GlyphandcogT1lib3T1lib XpdfXpdfreaderApr 29, 2026 Mar 31, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a craft...Show more |
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (applica...Show more |
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally re...Show more |