← Back

CVE-2016-2802

nvd nist
Published: Mar 13, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

Affected (22)

Products: Mozilla: Firefox · Opensuse: Leap, Opensuse · Suse: Linux Enterprise · +2 more
Show all products
1 product
Firefox
2 products
Leap
Opensuse
1 product
Linux Enterprise
1 product
Graphite2
1 product
Linux
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 44.0.2
Version 38.0.1
Version 38.0.5
Version 38.0
Version 38.1.0
Version 38.1.1
Version 38.2.0
Version 38.2.1
Version 38.3.0
Version 38.4.0
Version 38.5.0
Version 38.5.1
Version 38.6.0
Version 38.6.1
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Opensuse
Version 13.1
Version 13.2
Version 12.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.3.5
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 5.0
Version 6
Version 7

References (52)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.