← Back

CVE-2016-2791

nvd nist
Published: Mar 13, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

Affected (22)

Products: Opensuse: Leap, Opensuse · Suse: Linux Enterprise · Mozilla: Firefox · +2 more
Show all products
2 products
Leap
Opensuse
1 product
Linux Enterprise
1 product
Firefox
1 product
Linux
1 product
Graphite2
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Opensuse
Version 13.1
Version 13.2
Version 12.0
Configuration B
14 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 44.0.2
Version 38.0.1
Version 38.0.5
Version 38.0
Version 38.1.0
Version 38.1.1
Version 38.2.0
Version 38.2.1
Version 38.3.0
Version 38.4.0
Version 38.5.0
Version 38.5.1
Version 38.6.0
Version 38.6.1
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 5.0
Version 6
Version 7
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.3.5

References (52)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.