cbcvebase.

Debian Graphite2 vulnerabilities

27 known vulnerabilities affecting debian/graphite2.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH24MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2016-2790HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2790 [HIGH] CVE-2016-2790: firefox - The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as use... The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font. Scope: local sid: resolved (f
debian
CVE-2016-2801HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2801 [HIGH] CVE-2016-2801: firefox - The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite... The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797. Scope
debian
CVE-2016-1977HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1977 [HIGH] CVE-2016-1977: firefox - The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.... The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2016-1526HIGHCVSS 8.1fixed in graphite2 1.3.5-1 (bookworm)2016
CVE-2016-1526 [HIGH] CVE-2016-1526: graphite2 - The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.... The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. Scope
debian
CVE-2016-2791HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2791 [HIGH] CVE-2016-2791: firefox - The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in... The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2016-1521HIGHCVSS 8.8fixed in graphite2 1.3.5-1 (bookworm)2016
CVE-2016-1521 [HIGH] CVE-2016-1521: graphite2 - The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, ... The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a craf
debian
CVE-2016-1523MEDIUMCVSS 6.5fixed in graphite2 1.3.5-1 (bookworm)2016
CVE-2016-1523 [MEDIUM] CVE-2016-1523: graphite2 - The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.... The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font. Scope: loca
debian