Sil Graphite2 vulnerabilities
27 known vulnerabilities affecting sil/graphite2.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH24MEDIUM1
Vulnerabilities
Page 2 of 2
CVE-2016-2791P3HIGHCVSS 8.8≤ 1.3.52016-03-13
CVE-2016-2791 [HIGH] CWE-119 CVE-2016-2791: The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox bef
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
nvdosv
CVE-2016-1969P3HIGHCVSS 8.8≤ 1.3.52016-03-13
CVE-2016-1969 [HIGH] CWE-119 CVE-2016-1969: The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
nvdosv
CVE-2018-7999P4HIGHCVSS 8.8v1.3.112018-03-09
CVE-2018-7999 [HIGH] CWE-476 CVE-2018-7999: In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.c
In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file.
nvdosv
CVE-2016-1526P4HIGHCVSS 8.1v1.2.42016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvdosv
CVE-2017-7777P4HIGHCVSS 8.8fixed in 1.3.102019-04-15
CVE-2017-7777 [HIGH] CWE-119 CVE-2017-7777: Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Load
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
nvdosv
CVE-2017-7771P4HIGHCVSS 8.1fixed in 1.3.102019-04-15
CVE-2017-7771 [HIGH] CWE-125 CVE-2017-7771: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
nvdosv
CVE-2016-1523P4MEDIUMCVSS 6.5v1.2.42016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvdosv
← Previous2 / 2