pango records
4 published records for vendor pango.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-189 Numeric Errors1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-12828Proof of concept | An issue was discovered in AnchorFree VPN SDK before 1.3.3.218.pango · virtual private network software development kit · CWE-434 | Critical9.8 | — | 3.3% | May 21, 2020 |
36Monitor | CVE-2011-0020Proof of concept | Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earliepango · pango · CWE-119 | High7.6 | — | 18.9% | Jan 24, 2011 |
31Monitor | CVE-2020-17365No exploit | Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potepango · hotspot shield · CWE-59 | High7.8 | — | 0.4% | Sep 24, 2020 |
28Monitor | CVE-2009-1194No exploit | Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers pango · pango · CWE-189 | Medium6.8 | — | 4.1% | May 11, 2009 |
- CVE-2020-1282840Plan
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218.
CriticalCVSS 9.8Proof of conceptEPSS 3%pango · virtual private network software development kitMay 21, 2020
- CVE-2011-002036Monitor
Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlie
HighCVSS 7.6Proof of conceptEPSS 19%pango · pangoJan 24, 2011
- CVE-2020-1736531Monitor
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to pote
HighCVSS 7.8No exploitEPSS 0%pango · hotspot shieldSep 24, 2020
- CVE-2009-119428Monitor
Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers
MediumCVSS 6.8No exploitEPSS 4%pango · pangoMay 11, 2009