cbcvebase.

Debian Graphite2 vulnerabilities

27 known vulnerabilities affecting debian/graphite2.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH24MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2016-2791P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2791 [HIGH] CVE-2016-2791: firefox - The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in... The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2016-1969P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1969 [HIGH] CVE-2016-1969: firefox - The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox befo... The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2018-7999P4HIGHCVSS 8.8fixed in graphite2 1.3.11-2 (bookworm)2018
CVE-2018-7999 [HIGH] CVE-2018-7999: graphite2 - In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability wa... In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file. Scope: local bookworm: resolved (fixed in 1.3.11-2) bullseye: resolved (fixed in 1.3.11-2) forky: resolved (f
debian
CVE-2016-1526P4HIGHCVSS 8.1fixed in graphite2 1.3.5-1 (bookworm)2016
CVE-2016-1526 [HIGH] CVE-2016-1526: graphite2 - The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.... The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. Scope
debian
CVE-2017-7777P4HIGHCVSS 8.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7777 [HIGH] CVE-2017-7777: firefox - Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphit... Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2017-7771P4HIGHCVSS 8.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7771 [HIGH] CVE-2017-7771: firefox - Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass:... Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2016-1523P4MEDIUMCVSS 6.5fixed in graphite2 1.3.5-1 (bookworm)2016
CVE-2016-1523 [MEDIUM] CVE-2016-1523: graphite2 - The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.... The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font. Scope: loca
debian
Debian Graphite2 vulnerabilities | cvebase