Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Graphite2
(Sil)Repositories | https://github.com/silnrsi/graphite |
#Vulnerabilities | 28 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2016-03-13 | CVE-2016-2793 | CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise | 8.8 | ||
2016-03-13 | CVE-2016-2792 | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800. | Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise | 8.8 | ||
2016-03-13 | CVE-2016-2791 | The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise | 8.8 | ||
2016-03-13 | CVE-2016-2790 | The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font. | Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise | 8.8 | ||
2016-03-13 | CVE-2016-1977 | The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font. | Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise | 8.8 | ||
2018-06-11 | CVE-2017-7778 | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. | Debian_linux, Firefox, Firefox_esr, Thunderbird, Graphite2 | 9.8 | ||
2019-04-15 | CVE-2017-7777 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | Firefox, Graphite2 | 8.8 | ||
2019-04-15 | CVE-2017-7776 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | Firefox, Graphite2 | 8.1 | ||
2019-04-15 | CVE-2017-7774 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | Firefox, Graphite2 | 9.1 | ||
2019-04-15 | CVE-2017-7773 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | Firefox, Graphite2 | 8.8 |