6.8
CVSSv2

CVE-2011-0064

Published: 07/03/2011 Updated: 14/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome pango 1.28.3

mozilla firefox

Vendor Advisories

Marc Schoenefeld discovered that Pango incorrectly handled certain Glyph Definition (GDEF) tables If a user were tricked into displaying text with a specially-crafted font, an attacker could cause Pango to crash, resulting in a denial of service This issue only affected Ubuntu 804 LTS and 910 (CVE-2010-0421) ...