8.1
CVSSv3

CVE-2016-1526

Published: 13/02/2016 Updated: 05/01/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox prior to 43.0 and Firefox ESR 38.x prior to 38.6.1, incorrectly validates a size value, which allows remote malicious users to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 7.0

mozilla firefox esr 38.2.1

mozilla firefox esr 38.1.1

mozilla firefox esr 38.0

mozilla thunderbird

mozilla firefox esr 38.5.2

mozilla firefox esr 38.5.1

mozilla firefox esr 38.3.0

mozilla firefox esr 38.2.0

mozilla firefox esr 38.1.0

mozilla firefox esr 38.5.0

mozilla firefox esr 38.4.0

mozilla firefox esr 38.0.5

mozilla firefox esr 38.0.1

mozilla firefox esr 38.6.0

sil graphite2 1.2.4

fedoraproject fedora 23

fedoraproject fedora 22

Vendor Advisories

graphite2 could be made to crash or run programs as your login if it opened a specially crafted font ...
Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed For the oldstable distribution (wheezy), these problems have been fixed in version 135-1~deb7u1 For the stable distribution (jessie), these problems have ...
Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code For the oldstable distribution (wheezy), this problem has been fixed in version 3861esr-1~deb7u1 For the stable distribution (jessie), this problem has been fixed in version 3861esr-1~deb8u1 For the ...
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service For the oldstable distribution (wheezy), these problems have been fixed in ...
Several vulnerabilities were discovered in Graphite2 An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application ...
A vulnerability has been discovered in Graphite2 An attacker able to trick an unsuspecting user into opening specially crafted font files in an application using Graphite2 could exploit these flaws to cause the application to crash or, potentially, execute arbitrary code with the privileges of the application ...