Subscribe via feed.
Archive for July, 2019

Microsoft DirectWrite / AFDKO OpenType blendArray Stack Corruption

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to incorrect handling of blendArray.

Microsoft DirectWrite / AFDKO readTTCDirectory Integer Overflow

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability due to integer overflow in readTTCDirectory.

Microsoft DirectWrite / AFDKO OpenType readStrings Buffer Overflow

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability in OpenType font handling in readStrings.

Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Out-Of-Bounds cubeStackDepth

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to out-of-bounds cubeStackDepth.

Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Negative cubeStackDepth

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to negative cubeStackDepth.

Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Negative nAxes

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to negative nAxes.

Microsoft DirectWrite / AFDKO do_set_weight_vector_cube Buffer Overflow

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a stack-based buffer overflow vulnerability in do_set_weight_vector_cube for large nAxes.

Microsoft DirectWrite / AFDKO Uninitialized Memory Use

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from an issue where it makes use of uninitialized memory while freeing resources in var_loadavar.

PowerPanel Business Edition 3.4.0 Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

PowerPanel Business Edition version 3.4.0 is vulnerable to cross site request forgery vulnerability. This can be exploited by tricking an authenticated user into visiting a web page controlled by a malicious person.

Microsoft DirectWrite / AFDKO OpenType Out-Of-Bounds Read / Write

Posted by deepcore under exploit (No Respond)

Microsoft DirectWrite / AFDKO suffers from a heap-based out-of-bounds read/write vulnerability in OpenType font handling due to unbounded iFD.