Filtered by vendor Sil
Subscribe
Total
28 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-1522 | 4 Debian, Fedoraproject, Mozilla and 1 more | 5 Debian Linux, Fedora, Firefox and 2 more | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font. | |||||
CVE-2016-1521 | 4 Debian, Fedoraproject, Mozilla and 1 more | 5 Debian Linux, Fedora, Firefox and 2 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font. | |||||
CVE-2017-7774 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 6.4 MEDIUM | 9.1 CRITICAL |
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | |||||
CVE-2017-7777 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 6.8 MEDIUM | 8.8 HIGH |
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | |||||
CVE-2017-7772 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 6.8 MEDIUM | 8.8 HIGH |
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | |||||
CVE-2017-7771 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 5.8 MEDIUM | 8.1 HIGH |
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | |||||
CVE-2017-7773 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 6.8 MEDIUM | 8.8 HIGH |
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | |||||
CVE-2017-7776 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-02-04 | 5.8 MEDIUM | 8.1 HIGH |
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. |