cairographics records
10 published records for vendor cairographics.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 80%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-121 Stack-based Buffer Overflow1
- CWE-125 Out-of-bounds Read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-416 Use After Free1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2017-9814No exploit | cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of miscairographics · cairo · CWE-125 | High7.5 | — | 3.4% | Jul 17, 2017 |
31Monitor | CVE-2016-3190No exploit | The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of sopensuse · opensuse · CWE-119 | High7.5 | — | 1.8% | Apr 21, 2016 |
31Monitor | CVE-2020-35492No exploit | A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4.cairographics · cairo · CWE-121 | High7.8 | — | 1.1% | Mar 18, 2021 |
27Monitor | CVE-2019-6462No exploit | An issue was discovered in cairo 1.16.0.cairographics · cairo · CWE-835 | Medium6.5 | — | 2.1% | Jan 16, 2019 |
27Monitor | CVE-2019-6461No exploit | An issue was discovered in cairo 1.16.0.cairographics · cairo · CWE-617 | Medium6.5 | — | 2.1% | Jan 16, 2019 |
27Monitor | CVE-2018-19876No exploit | cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMallcairographics · cairo · CWE-416 | Medium6.5 | — | 1.7% | Dec 5, 2018 |
26Monitor | CVE-2018-18064No exploit | cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interacticairographics · cairo · CWE-787 | Medium6.5 | — | 1.5% | Oct 8, 2018 |
23Monitor | CVE-2016-9082No exploit | Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereferencecairographics · cairo · CWE-190 | Medium5.5 | — | 2.0% | Feb 3, 2017 |
23Monitor | CVE-2017-7475No exploit | Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an applicatiocairographics · cairo · CWE-476 | Medium5.5 | — | 1.8% | May 19, 2017 |
22Monitor | CVE-2014-5116Proof of concept | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denicairographics · cairo | Medium5.0 | — | 7.6% | Jul 29, 2014 |
- CVE-2017-981431Monitor
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mis
HighCVSS 7.5No exploitEPSS 3%cairographics · cairoJul 17, 2017
- CVE-2016-319031Monitor
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of s
HighCVSS 7.5No exploitEPSS 2%opensuse · opensuseApr 21, 2016
- CVE-2020-3549231Monitor
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4.
HighCVSS 7.8No exploitEPSS 1%cairographics · cairoMar 18, 2021
- CVE-2019-646227Monitor
An issue was discovered in cairo 1.16.0.
MediumCVSS 6.5No exploitEPSS 2%cairographics · cairoJan 16, 2019
- CVE-2019-646127Monitor
An issue was discovered in cairo 1.16.0.
MediumCVSS 6.5No exploitEPSS 2%cairographics · cairoJan 16, 2019
- CVE-2018-1987627Monitor
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMall
MediumCVSS 6.5No exploitEPSS 2%cairographics · cairoDec 5, 2018
- CVE-2018-1806426Monitor
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interacti
MediumCVSS 6.5No exploitEPSS 1%cairographics · cairoOct 8, 2018
- CVE-2016-908223Monitor
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference
MediumCVSS 5.5No exploitEPSS 2%cairographics · cairoFeb 3, 2017
- CVE-2017-747523Monitor
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an applicatio
MediumCVSS 5.5No exploitEPSS 2%cairographics · cairoMay 19, 2017
- CVE-2014-511622Monitor
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a deni
MediumCVSS 5.0Proof of conceptEPSS 8%cairographics · cairoJul 29, 2014