Search CVE reports
21 – 27 of 27 results
CVE-2016-2790
Medium prioritySome fixes available 14 of 15
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote...
3 affected packages
firefox, graphite2, thunderbird
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
firefox | — | — | — | — | Not affected |
graphite2 | — | — | — | — | Fixed |
thunderbird | — | — | — | — | Fixed |
CVE-2016-1977
Medium prioritySome fixes available 14 of 15
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of...
3 affected packages
firefox, graphite2, thunderbird
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
firefox | — | — | — | — | Not affected |
graphite2 | — | — | — | — | Fixed |
thunderbird | — | — | — | — | Fixed |
CVE-2016-1526
Low prioritySome fixes available 5 of 6
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to...
1 affected packages
graphite2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
graphite2 | — | — | — | — | Fixed |
CVE-2016-1523
Medium prioritySome fixes available 11 of 13
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause...
2 affected packages
graphite2, thunderbird
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
graphite2 | — | — | — | — | Fixed |
thunderbird | — | — | — | — | Fixed |
CVE-2016-1522
Medium prioritySome fixes available 5 of 6
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of...
1 affected packages
graphite2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
graphite2 | — | — | — | — | Fixed |
CVE-2016-1521
Medium prioritySome fixes available 5 of 6
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers...
1 affected packages
graphite2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
graphite2 | — | — | — | — | Fixed |
CVE-2012-3971
Medium prioritySome fixes available 28 of 39
Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory...
6 affected packages
firefox, graphite2, seamonkey, thunderbird, xulrunner-1.9.2, xulrunner-2.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
firefox | — | — | — | — | Fixed |
graphite2 | — | — | — | — | Not affected |
seamonkey | — | — | — | — | Not in release |
thunderbird | — | — | — | — | Fixed |
xulrunner-1.9.2 | — | — | — | — | Not in release |
xulrunner-2.0 | — | — | — | — | Not in release |