t1lib records
8 published records for vendor t1lib.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-189 Numeric Errors2
- CWE-20 Improper Input Validation1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2007-4033Proof of concept | Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute at1lib · t1lib · CWE-119 | High7.5 | — | 18.7% | Jul 27, 2007 |
34Monitor | CVE-2010-2642No exploit | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possit1lib · t1lib · CWE-119 | High7.6 | — | 14.3% | Jan 7, 2011 |
31Monitor | CVE-2011-0764No exploit | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenct1lib · t1lib · CWE-20 | Medium6.8 | — | 13.1% | Mar 31, 2011 |
28Monitor | CVE-2011-0433No exploit | Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other producgnome · evince · CWE-119 | Medium6.8 | — | 4.2% | Nov 19, 2012 |
28Monitor | CVE-2011-5244No exploit | Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x,t1lib · t1lib · CWE-189 | Medium6.8 | — | 3.4% | Nov 19, 2012 |
20Monitor | CVE-2011-1552No exploit | t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remotet1lib · t1lib · CWE-119 | Medium4.3 | — | 10.4% | Mar 31, 2011 |
19Monitor | CVE-2011-1553No exploit | Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers t1lib · t1lib · CWE-399 | Medium4.3 | — | 5.4% | Mar 31, 2011 |
19Monitor | CVE-2011-1554No exploit | Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a dt1lib · t1lib · CWE-189 | Medium4.3 | — | 5.4% | Mar 31, 2011 |
- CVE-2007-403336Monitor
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 19%t1lib · t1libJul 27, 2007
- CVE-2010-264234Monitor
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi
HighCVSS 7.6No exploitEPSS 14%t1lib · t1libJan 7, 2011
- CVE-2011-076431Monitor
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereferenc
MediumCVSS 6.8No exploitEPSS 13%t1lib · t1libMar 31, 2011
- CVE-2011-043328Monitor
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other produc
MediumCVSS 6.8No exploitEPSS 4%gnome · evinceNov 19, 2012
- CVE-2011-524428Monitor
Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x,
MediumCVSS 6.8No exploitEPSS 3%t1lib · t1libNov 19, 2012
- CVE-2011-155220Monitor
t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote
MediumCVSS 4.3No exploitEPSS 10%t1lib · t1libMar 31, 2011
- CVE-2011-155319Monitor
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers
MediumCVSS 4.3No exploitEPSS 5%t1lib · t1libMar 31, 2011
- CVE-2011-155419Monitor
Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a d
MediumCVSS 4.3No exploitEPSS 5%t1lib · t1libMar 31, 2011