Lucene search

K
cve[email protected]CVE-2009-0946
HistoryApr 17, 2009 - 12:30 a.m.

CVE-2009-0946

2009-04-1700:30:00
CWE-190
web.nvd.nist.gov
56
cve-2009-0946
freetype
integer overflow
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.7%

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

Affected configurations

NVD
Node
freetypefreetypeRange≀2.3.9
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
canonicalubuntu_linuxMatch6.06
OR
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch8.10
OR
canonicalubuntu_linuxMatch9.04
Node
opensuseopensuseMatch10.3
OR
opensuseopensuseMatch11.0
OR
opensuseopensuseMatch11.1
OR
suselinux_enterprise_serverMatch10-
OR
suselinux_enterprise_serverMatch11-
Node
applesafariMatch4.0
OR
appleiphone_osRange1.0.0–2.2.1
OR
applemac_os_xRange10.6.0–10.6.4
OR
applemac_os_xMatch10.4.11
OR
applemac_os_xMatch10.5.8
OR
applemac_os_x_serverRange10.6.0–10.6.4
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5.8
CPENameOperatorVersion
freetype:freetypefreetypele2.3.9

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.7%