Записи cairographics
10 опубликованных записей вендора cairographics.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-121 Stack-based Buffer Overflow1
- CWE-125 Out-of-bounds Read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-416 Use After Free1
- CWE-476 NULL Pointer Dereference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2017-9814Эксплойта нет | cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of miscairographics · cairo · CWE-125 | Высокая7,5 | — | 3,4 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2016-3190Эксплойта нет | The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of sopensuse · opensuse · CWE-119 | Высокая7,5 | — | 1,8 % | 21 апр. 2016 г. |
31Наблюдать | CVE-2020-35492Эксплойта нет | A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4.cairographics · cairo · CWE-121 | Высокая7,8 | — | 1,1 % | 18 мар. 2021 г. |
27Наблюдать | CVE-2019-6462Эксплойта нет | An issue was discovered in cairo 1.16.0.cairographics · cairo · CWE-835 | Средняя6,5 | — | 2,1 % | 16 янв. 2019 г. |
27Наблюдать | CVE-2019-6461Эксплойта нет | An issue was discovered in cairo 1.16.0.cairographics · cairo · CWE-617 | Средняя6,5 | — | 2,1 % | 16 янв. 2019 г. |
27Наблюдать | CVE-2018-19876Эксплойта нет | cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMallcairographics · cairo · CWE-416 | Средняя6,5 | — | 1,7 % | 5 дек. 2018 г. |
26Наблюдать | CVE-2018-18064Эксплойта нет | cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interacticairographics · cairo · CWE-787 | Средняя6,5 | — | 1,5 % | 8 окт. 2018 г. |
23Наблюдать | CVE-2016-9082Эксплойта нет | Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereferencecairographics · cairo · CWE-190 | Средняя5,5 | — | 2,0 % | 3 февр. 2017 г. |
23Наблюдать | CVE-2017-7475Эксплойта нет | Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an applicatiocairographics · cairo · CWE-476 | Средняя5,5 | — | 1,8 % | 19 мая 2017 г. |
22Наблюдать | CVE-2014-5116Proof of concept | The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denicairographics · cairo | Средняя5,0 | — | 7,6 % | 29 июл. 2014 г. |
- CVE-2017-981431Наблюдать
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mis
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cairographics · cairo17 июл. 2017 г.
- CVE-2016-319031Наблюдать
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of s
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opensuse · opensuse21 апр. 2016 г.
- CVE-2020-3549231Наблюдать
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %cairographics · cairo18 мар. 2021 г.
- CVE-2019-646227Наблюдать
An issue was discovered in cairo 1.16.0.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %cairographics · cairo16 янв. 2019 г.
- CVE-2019-646127Наблюдать
An issue was discovered in cairo 1.16.0.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %cairographics · cairo16 янв. 2019 г.
- CVE-2018-1987627Наблюдать
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMall
СредняяCVSS 6,5Эксплойта нетEPSS 2 %cairographics · cairo5 дек. 2018 г.
- CVE-2018-1806426Наблюдать
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interacti
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cairographics · cairo8 окт. 2018 г.
- CVE-2016-908223Наблюдать
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference
СредняяCVSS 5,5Эксплойта нетEPSS 2 %cairographics · cairo3 февр. 2017 г.
- CVE-2017-747523Наблюдать
Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an applicatio
СредняяCVSS 5,5Эксплойта нетEPSS 2 %cairographics · cairo19 мая 2017 г.
- CVE-2014-511622Наблюдать
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a deni
СредняяCVSS 5,0Proof of conceptEPSS 8 %cairographics · cairo29 июл. 2014 г.