Lucene search

K

Pango Security Vulnerabilities

cve
cve

CVE-2009-1194

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as...

8.1AI Score

0.004EPSS

2009-05-11 03:30 PM
45
cve
cve

CVE-2011-0020

Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary....

8.2AI Score

0.186EPSS

2011-01-24 06:00 PM
42
cve
cve

CVE-2020-17365

Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially...

7.8CVSS

7.8AI Score

0.0004EPSS

2020-09-24 11:15 PM
24
cve
cve

CVE-2020-12828

An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM....

9.8CVSS

9.3AI Score

0.002EPSS

2020-05-21 05:15 PM
25