sil records
28 published records for vendor sil.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer20
- CWE-125 Out-of-bounds Read3
- CWE-19 Data Processing Errors2
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
28 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-7778No exploit | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use mozilla · firefox · CWE-119 | Critical9.8 | — | 5.2% | Jun 11, 2018 |
37Monitor | CVE-2016-1522No exploit | Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider remozilla · firefox · CWE-119 | High8.8 | — | 8.3% | Feb 12, 2016 |
36Monitor | CVE-2016-2799No exploit | Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Fmozilla · firefox · CWE-119 | High8.8 | — | 4.9% | Mar 13, 2016 |
36Monitor | CVE-2016-1521No exploit | The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x mozilla · firefox · CWE-119 | High8.8 | — | 4.1% | Feb 12, 2016 |
36Monitor | CVE-2016-2796No exploit | Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before mozilla · firefox · CWE-119 | High8.8 | — | 3.9% | Mar 13, 2016 |
36Monitor | CVE-2016-2794No exploit | The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox mozilla · firefox · CWE-119 | High8.8 | — | 3.5% | Mar 13, 2016 |
36Monitor | CVE-2016-1977No exploit | The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38mozilla · firefox · CWE-119 | High8.8 | — | 2.9% | Mar 13, 2016 |
36Monitor | CVE-2016-2797No exploit | The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.mozilla · firefox · CWE-119 | High8.8 | — | 2.7% | Mar 13, 2016 |
36Monitor | CVE-2016-2793No exploit | CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers mozilla · firefox · CWE-119 | High8.8 | — | 2.7% | Mar 13, 2016 |
36Monitor | CVE-2017-5436No exploit | An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.debian · debian linux · CWE-787 | High8.8 | — | 2.4% | Jun 11, 2018 |
36Monitor | CVE-2016-2798No exploit | The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bmozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2790No exploit | The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x beforemozilla · firefox · CWE-19 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2791No exploit | The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.mozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2792No exploit | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bemozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2795No exploit | The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x beformozilla · firefox · CWE-19 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2800No exploit | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bemozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2801No exploit | The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and mozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2016-2802No exploit | The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox Emozilla · firefox · CWE-119 | High8.8 | — | 2.3% | Mar 13, 2016 |
36Monitor | CVE-2018-7999No exploit | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, whisil · graphite2 · CWE-476 | High8.8 | — | 2.2% | Mar 9, 2018 |
36Monitor | CVE-2017-7774No exploit | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.sil · graphite2 · CWE-125 | Critical9.1 | — | 1.4% | Apr 15, 2019 |
35Monitor | CVE-2016-1969No exploit | The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote atmozilla · firefox · CWE-119 | High8.8 | — | 1.7% | Mar 13, 2016 |
35Monitor | CVE-2017-7772No exploit | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.mozilla · firefox · CWE-119 | High8.8 | — | 1.4% | Apr 12, 2019 |
35Monitor | CVE-2017-7773No exploit | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.mozilla · firefox · CWE-119 | High8.8 | — | 1.4% | Apr 15, 2019 |
35Monitor | CVE-2017-7777No exploit | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.mozilla · firefox · CWE-119 | High8.8 | — | 1.2% | Apr 15, 2019 |
33Monitor | CVE-2017-7776No exploit | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.sil · graphite2 · CWE-125 | High8.1 | — | 2.8% | Apr 15, 2019 |
- CVE-2017-777841Plan
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use
CriticalCVSS 9.8No exploitEPSS 5%mozilla · firefoxJun 11, 2018
- CVE-2016-152237Monitor
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider re
HighCVSS 8.8No exploitEPSS 8%mozilla · firefoxFeb 12, 2016
- CVE-2016-279936Monitor
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and F
HighCVSS 8.8No exploitEPSS 5%mozilla · firefoxMar 13, 2016
- CVE-2016-152136Monitor
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x
HighCVSS 8.8No exploitEPSS 4%mozilla · firefoxFeb 12, 2016
- CVE-2016-279636Monitor
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
HighCVSS 8.8No exploitEPSS 4%mozilla · firefoxMar 13, 2016
- CVE-2016-279436Monitor
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox
HighCVSS 8.8No exploitEPSS 3%mozilla · firefoxMar 13, 2016
- CVE-2016-197736Monitor
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38
HighCVSS 8.8No exploitEPSS 3%mozilla · firefoxMar 13, 2016
- CVE-2016-279736Monitor
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.
HighCVSS 8.8No exploitEPSS 3%mozilla · firefoxMar 13, 2016
- CVE-2016-279336Monitor
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers
HighCVSS 8.8No exploitEPSS 3%mozilla · firefoxMar 13, 2016
- CVE-2017-543636Monitor
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.
HighCVSS 8.8No exploitEPSS 2%debian · debian linuxJun 11, 2018
- CVE-2016-279836Monitor
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x b
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-279036Monitor
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-279136Monitor
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-279236Monitor
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-279536Monitor
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x befor
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-280036Monitor
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-280136Monitor
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2016-280236Monitor
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2018-799936Monitor
In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, whi
HighCVSS 8.8No exploitEPSS 2%sil · graphite2Mar 9, 2018
- CVE-2017-777436Monitor
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
CriticalCVSS 9.1No exploitEPSS 1%sil · graphite2Apr 15, 2019
- CVE-2016-196935Monitor
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote at
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxMar 13, 2016
- CVE-2017-777235Monitor
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxApr 12, 2019
- CVE-2017-777335Monitor
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxApr 15, 2019
- CVE-2017-777735Monitor
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxApr 15, 2019
- CVE-2017-777633Monitor
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
HighCVSS 8.1No exploitEPSS 3%sil · graphite2Apr 15, 2019