cvedb.io
CVE-2018-6917
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2018-04-04T14:29:00.247 · Last modified 2026-06-17T02:02:27.547

Summary

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.

Affected products

freebsd — freebsd

Does this affect you?

Add your gear to cvedb and we'll alert you only when freebsd ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.