SIL
SIL Graphite2: vulnerabilidades y CVE
SIL Graphite2 tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-7777 | Alta (8.8) | 1.2% | — | 15 abr 2019 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. |
| CVE-2017-7776 | Alta (8.1) | 2.8% | — | 15 abr 2019 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. |
| CVE-2017-7774 | Crítica (9.1) | 1.4% | — | 15 abr 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. |
| CVE-2017-7773 | Alta (8.8) | 1.4% | — | 15 abr 2019 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. |
| CVE-2017-7771 | Alta (8.1) | 1.2% | — | 15 abr 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. |
| CVE-2017-7772 | Alta (8.8) | 1.4% | — | 12 abr 2019 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. |
| CVE-2017-7778 | Crítica (9.8) | 5.1% | — | 11 jun 2018 | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version… |
| CVE-2017-5436 | Alta (8.8) | 2.4% | — | 11 jun 2018 | An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla… |
| CVE-2018-7999 | Alta (8.8) | 2.2% | — | 9 mar 2018 | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have… |
| CVE-2016-2802 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service… |
| CVE-2016-2801 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of… |
| CVE-2016-2800 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer… |
| CVE-2016-2799 | Alta (8.8) | 4.9% | — | 13 mar 2016 | Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of… |
| CVE-2016-2798 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer… |
| CVE-2016-2797 | Alta (8.8) | 2.7% | — | 13 mar 2016 | The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer… |
| CVE-2016-2796 | Alta (8.8) | 3.9% | — | 13 mar 2016 | Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a… |
| CVE-2016-2795 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which… |
| CVE-2016-2794 | Alta (8.8) | 3.5% | — | 13 mar 2016 | The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service… |
| CVE-2016-2793 | Alta (8.8) | 2.7% | — | 13 mar 2016 | CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified… |
| CVE-2016-2792 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer… |
| CVE-2016-2791 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or… |
| CVE-2016-2790 | Alta (8.8) | 2.3% | — | 13 mar 2016 | The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which… |
| CVE-2016-1977 | Alta (8.8) | 2.9% | — | 13 mar 2016 | The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a… |
| CVE-2016-1969 | Alta (8.8) | 1.7% | — | 13 mar 2016 | The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have… |
| CVE-2016-1526 | Alta (8.1) | 2.3% | — | 13 feb 2016 | The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote… |
| CVE-2016-1523 | Media (6.5) | 2.3% | — | 13 feb 2016 | The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to… |
| CVE-2016-1522 | Alta (8.8) | 8.3% | — | 13 feb 2016 | Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause… |
| CVE-2016-1521 | Alta (8.8) | 4.1% | — | 13 feb 2016 | The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote… |