CVE-2016-4852

YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesetter API on OS X 10.9, which allows remote attackers to cause a denial of service (application crash) via a crafted emoji character sequence.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:aki-null:yorufukurou:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:10.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.9.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.9.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.9.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.9.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.9.5:*:*:*:*:*:*:*

History

21 Nov 2024, 02:53

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN94816361/995844/index.html - Third Party Advisory () http://jvn.jp/en/jp/JVN94816361/995844/index.html - Third Party Advisory
References () http://jvn.jp/en/jp/JVN94816361/index.html - Third Party Advisory () http://jvn.jp/en/jp/JVN94816361/index.html - Third Party Advisory
References () http://jvndb.jvn.jp/jvndb/JVNDB-2016-000151 - Third Party Advisory, VDB Entry () http://jvndb.jvn.jp/jvndb/JVNDB-2016-000151 - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/92609 - () http://www.securityfocus.com/bid/92609 -

Information

Published : 2016-09-12 10:59

Updated : 2024-11-21 02:53


NVD link : CVE-2016-4852

Mitre link : CVE-2016-4852

CVE.ORG link : CVE-2016-4852


JSON object : View

Products Affected

aki-null

  • yorufukurou

apple

  • mac_os_x
CWE
CWE-20

Improper Input Validation