Known Vulnerabilities for products from T1lib

Listed below are 8 of the newest known vulnerabilities associated with the vendor "T1lib".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2011-5244 Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used ... 6.8 - MEDIUM 2012-11-19 2017-08-29
CVE-2011-1554 Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attacke... 4.3 - MEDIUM 2011-03-31 2019-03-06
CVE-2011-1553 Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows re... 4.3 - MEDIUM 2011-03-31 2019-03-06
CVE-2011-1552 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, whic... 4.3 - MEDIUM 2011-03-31 2019-03-06
CVE-2011-0764 t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction wi... 6.8 - MEDIUM 2011-03-31 2019-03-06
CVE-2011-0433 Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possib... 6.8 - MEDIUM 2012-11-19 2017-07-01
CVE-2010-2642 Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5... 7.6 - HIGH 2011-01-07 2017-07-01
CVE-2007-4033 Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attacke... 7.5 - HIGH 2007-07-27 2018-10-15

Known software with vulnerabilities from T1lib

Type Vendor Product Version
ApplicationT1libT1lib0.1