CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | 8.8 |
Haute |
||
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | 8.1 |
Haute |
||
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | 9.1 |
Critique |
||
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | 8.8 |
Haute |
||
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | 8.1 |
Haute |
||
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | 8.8 |
Haute |
||
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. | 9.8 |
Critique |