GNOME Pango 1.28.3

CPE Details

GNOME Pango 1.28.3
1.28.3
2021-07-14
13h38 +00:00
2021-07-14
13h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnome:pango:1.28.3:*:*:*:*:*:*:*

Informations

Vendor

gnome

Product

pango

Version

1.28.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-0064 2011-03-07 19h00 +00:00 The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.
6.8
CVE-2011-0020 2011-01-24 16h00 +00:00 Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.
7.6