Gnome Libgxps vulnerabilities
3 known vulnerabilities affecting gnome/libgxps.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-10767MEDIUMCVSS 6.5≤ 0.3.02018-05-06
CVE-2018-10767 [MEDIUM] CWE-125 CVE-2018-10767: There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_ty
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
nvdosv
CVE-2018-10733MEDIUMCVSS 6.5≤ 0.3.02018-05-04
CVE-2018-10733 [MEDIUM] CWE-125 CVE-2018-10733: There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
nvdosv
CVE-2017-11590HIGHCVSS 7.5v0.2.52017-07-24
CVE-2017-11590 [HIGH] CWE-476 CVE-2017-11590: There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5
There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
nvdosv