cbcvebase.
CVE-2009-0946
published 2009-04-17

CVE-2009-0946: Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleiphone_os1.0.0 – 2.2.1
applemac_os_x
applemac_os_x
applemac_os_x10.6.0 – 10.6.4
applemac_os_x_server
applemac_os_x_server
applemac_os_x_server10.6.0 – 10.6.4
applesafari
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfreetype< freetype 2.3.9-4.1 (bookworm)freetype 2.3.9-4.1 (bookworm)
freetypefreetype<= 2.3.9
freetypefreetype>= 0 < 2.3.9-4.12.3.9-4.1
freetypefreetype>= 0 < 2.3.9-4.12.3.9-4.1
freetypefreetype>= 0 < 2.3.9-4.12.3.9-4.1
freetypefreetype>= 0 < 2.3.9-4.12.3.9-4.1
opensuseopensuse
opensuseopensuse
opensuseopensuse
suselinux_enterprise_server

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH