Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Mozilla FirefoxSIL Graphite2 | 15/4/2019 | 17/6/2026 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | |
| Modificada | Alta (8.1) | 2.8% | — | Mozilla FirefoxSIL Graphite2 | 15/4/2019 | 17/6/2026 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | |
| Modificada | Crítica (9.1) | 1.4% | — | Mozilla FirefoxSIL Graphite2 | 15/4/2019 | 17/6/2026 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | |
| Modificada | Alta (8.8) | 1.4% | — | Mozilla FirefoxSIL Graphite2 | 15/4/2019 | 17/6/2026 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | |
| Modificada | Alta (8.1) | 1.2% | — | Mozilla FirefoxSIL Graphite2 | 15/4/2019 | 17/6/2026 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | |
| Modificada | Alta (8.8) | 1.4% | — | Mozilla FirefoxSIL Graphite2 | 12/4/2019 | 17/6/2026 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | |
| Modificada | Crítica (9.8) | 5.1% | — | Mozilla FirefoxMozilla ThunderbirdDebian LinuxSIL Graphite2 | 11/6/2018 | 17/6/2026 | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. | |
| Modificada | Alta (8.8) | 2.4% | — | Debian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+6 | 11/6/2018 | 17/6/2026 | An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and… | |
| Modificada | Alta (8.8) | 2.2% | — | SIL Graphite2 | 9/3/2018 | 17/6/2026 | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file. | |
| Modificada | Alta (8.8) | 2.3% | — | Mozilla FirefoxOpensuse LeapOpensuseSuse Linux Enterprise+2 | 13/3/2016 | 17/6/2026 | The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.3% | — | Opensuse LeapOpensuseSuse Linux EnterpriseSIL Graphite2+2 | 13/3/2016 | 17/6/2026 | The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font,… | |
| Modificada | Alta (8.8) | 2.3% | — | Mozilla FirefoxOpensuse LeapOpensuseSuse Linux Enterprise+2 | 13/3/2016 | 17/6/2026 | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different… | |
| Modificada | Alta (8.8) | 4.9% | — | Oracle LinuxOpensuse LeapOpensuseSuse Linux Enterprise+2 | 13/3/2016 | 17/6/2026 | Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.3% | — | Mozilla FirefoxSIL Graphite2Oracle LinuxOpensuse Leap+2 | 13/3/2016 | 17/6/2026 | The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.7% | — | Oracle LinuxMozilla FirefoxOpensuse LeapOpensuse+2 | 13/3/2016 | 17/6/2026 | The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different… | |
| Modificada | Alta (8.8) | 3.9% | — | SIL Graphite2Opensuse LeapOpensuseSuse Linux Enterprise+2 | 13/3/2016 | 17/6/2026 | Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.3% | — | Opensuse LeapOpensuseSuse Linux EnterpriseOracle Linux+2 | 13/3/2016 | 17/6/2026 | The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a… | |
| Modificada | Alta (8.8) | 3.5% | — | Mozilla FirefoxSIL Graphite2Opensuse LeapOpensuse+2 | 13/3/2016 | 17/6/2026 | The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.7% | — | Oracle LinuxMozilla FirefoxSIL Graphite2Opensuse Leap+2 | 13/3/2016 | 17/6/2026 | CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.3% | — | SIL Graphite2Mozilla FirefoxOracle LinuxOpensuse Leap+2 | 13/3/2016 | 17/6/2026 | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different… | |
| Modificada | Alta (8.8) | 2.3% | — | Opensuse LeapOpensuseSuse Linux EnterpriseMozilla Firefox+2 | 13/3/2016 | 17/6/2026 | The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 2.3% | — | Opensuse LeapOpensuseSuse Linux EnterpriseMozilla Firefox+2 | 13/3/2016 | 17/6/2026 | The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted… | |
| Modificada | Alta (8.8) | 2.9% | — | Opensuse LeapOpensuseSuse Linux EnterpriseOracle Linux+2 | 13/3/2016 | 17/6/2026 | The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font. | |
| Modificada | Alta (8.8) | 1.7% | — | SIL Graphite2Mozilla Firefox | 13/3/2016 | 17/6/2026 | The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font. | |
| Modificada | Alta (8.1) | 2.3% | — | Debian LinuxMozilla FirefoxMozilla ThunderbirdSIL Graphite2+1 | 13/2/2016 | 17/6/2026 | The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and… |