Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 27 of 27 results


CVE-2016-2790

Medium priority

Some fixes available 14 of 15

The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote...

3 affected packages

firefox, graphite2, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
firefox Not affected
graphite2 Fixed
thunderbird Fixed
Show less packages

CVE-2016-1977

Medium priority

Some fixes available 14 of 15

The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of...

3 affected packages

firefox, graphite2, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
firefox Not affected
graphite2 Fixed
thunderbird Fixed
Show less packages

CVE-2016-1526

Low priority

Some fixes available 5 of 6

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to...

1 affected packages

graphite2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
graphite2 Fixed
Show less packages

CVE-2016-1523

Medium priority

Some fixes available 11 of 13

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause...

2 affected packages

graphite2, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
graphite2 Fixed
thunderbird Fixed
Show less packages

CVE-2016-1522

Medium priority

Some fixes available 5 of 6

Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of...

1 affected packages

graphite2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
graphite2 Fixed
Show less packages

CVE-2016-1521

Medium priority

Some fixes available 5 of 6

The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers...

1 affected packages

graphite2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
graphite2 Fixed
Show less packages

CVE-2012-3971

Medium priority

Some fixes available 28 of 39

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory...

6 affected packages

firefox, graphite2, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
firefox Fixed
graphite2 Not affected
seamonkey Not in release
thunderbird Fixed
xulrunner-1.9.2 Not in release
xulrunner-2.0 Not in release
Show less packages