Harfbuzz Project
harfbuzz_project
7 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if...Show more |
2Fedoraproject Harfbuzz Project2Fedora HarfbuzzMar 25, 2025 Feb 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. |
2Fedoraproject Harfbuzz Project2Fedora HarfbuzzNov 21, 2024 Jun 23, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors. |
2Fedoraproject Harfbuzz Project2Fedora HarfbuzzNov 21, 2024 Jan 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy). |
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout...Show more |
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2...Show more |
2Google Harfbuzz Project2Chrome HarfbuzzMay 6, 2026 Jan 25, 2016 N/A· v4 7.6 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by...Show more |