Vulnerabilities (CVE)

Filtered by vendor Truecrypt Project Subscribe
Filtered by product Truecrypt
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-2884 1 Truecrypt Project 1 Truecrypt 2024-02-04 2.1 LOW 3.3 LOW
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.
CVE-2014-2885 1 Truecrypt Project 1 Truecrypt 2024-02-04 3.6 LOW 7.1 HIGH
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.