Debian Cairo vulnerabilities
11 known vulnerabilities affecting debian/cairo.
Total CVEs
11
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2LOW7
Vulnerabilities
Page 1 of 1
CVE-2025-50422LOWCVSS 2.92025
CVE-2025-50422 [LOW] CVE-2025-50422: cairo - Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face...
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2020-35492HIGHCVSS 7.8fixed in cairo 1.16.0-5 (bookworm)2020
CVE-2020-35492 [HIGH] CVE-2020-35492: cairo - A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. ...
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The hi
debian
CVE-2019-6461LOWCVSS 6.5fixed in cairo 1.18.0-1 (forky)2019
CVE-2019-6461 [MEDIUM] CVE-2019-6461: cairo - An issue was discovered in cairo 1.16.0. There is an assertion problem in the fu...
An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.18.0-1)
sid: resolved (fixed in 1.18.0-1)
trixie: resolved (fixed in 1.18.0-1)
debian
CVE-2019-6462LOWCVSS 6.5fixed in cairo 1.17.8-3 (forky)2019
CVE-2019-6462 [MEDIUM] CVE-2019-6462: cairo - An issue was discovered in cairo 1.16.0. There is an infinite loop in the functi...
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.17.8-3)
sid: resolved (fixed in 1.17.8-3)
trixie: resolved (fixed in 1.17.8-3)
debian
CVE-2018-19876MEDIUMCVSS 6.5fixed in cairo 1.16.0-4 (bookworm)2018
CVE-2018-19876 [MEDIUM] CVE-2018-19876: cairo - cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memo...
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.
Scope: local
bookworm: resolved (fixed in 1.16.0-4)
bullseye: resolved (fixed in 1.16.0-4)
forky: resolved (fixed in 1.16.0-4)
sid: resolved (fixed in 1
debian
CVE-2018-18064LOWCVSS 6.52018
CVE-2018-18064 [MEDIUM] CVE-2018-18064: cairo - cairo through 1.15.14 has an out-of-bounds stack-memory write during processing ...
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
tri
debian
CVE-2017-9814LOWCVSS 7.5fixed in cairo 1.16.0-1 (bookworm)2017
CVE-2017-9814 [HIGH] CVE-2017-9814: cairo - cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to c...
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
Scope: local
bookworm: resolved (fixed in 1.16.0-1)
bullseye: resolved (fixed in 1.16.0-1)
forky: resolved (fixed in 1.16.0-1)
sid: resolved (fixed in 1.16.0-1)
trixie: resolved (fixed in 1.
debian
CVE-2017-7475LOWCVSS 5.52017
CVE-2017-7475 [MEDIUM] CVE-2017-7475: cairo - Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the ...
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2016-3190HIGHCVSS 7.5fixed in cairo 1.14.2-2 (bookworm)2016
CVE-2016-3190 [HIGH] CVE-2016-3190: cairo - The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo ...
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length.
Scope: local
bookworm: resolved (fixed in 1.14.2-2)
bullseye: resolved (fixed in 1.14.2-2)
forky: resolved (fixed in 1.14.2-2)
sid: resolved (fixed in 1.1
debian
CVE-2016-9082MEDIUMCVSS 5.5fixed in cairo 1.14.6-1.1 (bookworm)2016
CVE-2016-9082 [MEDIUM] CVE-2016-9082: cairo - Integer overflow in the write_png function in cairo 1.14.6 allows remote attacke...
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
Scope: local
bookworm: resolved (fixed in 1.14.6-1.1)
bullseye: resolved (fixed in 1.14.6-1.1)
forky: resolved (fixed in 1.14.6-1.1)
sid: resolved (fixed in 1.14.6-1.1)
trixie: resolved (fixed in 1.14.6-1.1
debian
CVE-2009-2044LOWCVSS 4.3PoCfixed in cairo 1.8.8-2 (bookworm)2009
CVE-2009-2044 [MEDIUM] CVE-2009-2044: cairo - Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a d...
Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.
Scope: local
bookworm: resolved (fixed in 1.8.8-2)
bullseye: resolved (fixed in 1.8.8-2)
forky: resolved (fixed in 1.8.8-2)
sid: resolved (fixed in 1.8.8-2)
trixie: resolved
debian