cbcvebase.

Sil Graphite2 vulnerabilities

27 known vulnerabilities affecting sil/graphite2.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH24MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2016-2791P3HIGHCVSS 8.8≤ 1.3.52016-03-13
CVE-2016-2791 [HIGH] CWE-119 CVE-2016-2791: The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox bef The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
nvdosv
CVE-2016-1969P3HIGHCVSS 8.8≤ 1.3.52016-03-13
CVE-2016-1969 [HIGH] CWE-119 CVE-2016-1969: The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
nvdosv
CVE-2018-7999P4HIGHCVSS 8.8v1.3.112018-03-09
CVE-2018-7999 [HIGH] CWE-476 CVE-2018-7999: In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.c In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file.
nvdosv
CVE-2016-1526P4HIGHCVSS 8.1v1.2.42016-02-13
CVE-2016-1526 [HIGH] CWE-119 CVE-2016-1526: The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozill The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smar
nvdosv
CVE-2017-7777P4HIGHCVSS 8.8fixed in 1.3.102019-04-15
CVE-2017-7777 [HIGH] CWE-119 CVE-2017-7777: Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Load Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
nvdosv
CVE-2017-7771P4HIGHCVSS 8.1fixed in 1.3.102019-04-15
CVE-2017-7771 [HIGH] CWE-125 CVE-2017-7771: Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
nvdosv
CVE-2016-1523P4MEDIUMCVSS 6.5v1.2.42016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvdosv
Sil Graphite2 vulnerabilities | cvebase