2016-03-13
|
CVE-2016-2802
|
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2801
|
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2800
|
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2799
|
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2798
|
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2797
|
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2796
|
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2795
|
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2794
|
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|
2016-03-13
|
CVE-2016-2793
|
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
|
Firefox, Firefox_esr, Leap, Opensuse, Linux, Graphite2, Linux_enterprise
|
8.8
|
|
|