|
198161
|
6.1 |
MEDIUM
Network
|
finecms
|
finecms
|
dayrui FineCms 5.0.9 has Cross Site Scripting (XSS) in admin/Login.php via a payload in the username field that does not begin with a '<' character.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11581
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198162
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11577
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198163
|
5.5 |
MEDIUM
Local
|
fontforge
|
fontforge
|
FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11576
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198164
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parset…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11575
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198165
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11574
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198166
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11573
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198167
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11572
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198168
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11571
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198169
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11570
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198170
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11569
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|