7.6
CVSSv3

CVE-2016-2052

Published: 25/01/2016 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.6 | Impact Score: 4.7 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple unspecified vulnerabilities in HarfBuzz prior to 1.0.6, as used in Google Chrome prior to 48.0.2564.82, allow malicious users to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

harfbuzz project harfbuzz

google chrome

Vendor Advisories

Several security issues were fixed in Oxide ...
HarfBuzz could be made to crash or run programs as your login if it processed specially crafted data ...
Multiple unspecified vulnerabilities in HarfBuzz before 106, as used in Google Chrome before 480256482, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-fontcc, a different issue than CVE-2015-8947 ...