Записи sil
28 опубликованных записей вендора sil.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer20
- CWE-125 Out-of-bounds Read3
- CWE-19 Data Processing Errors2
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2017-7778Эксплойта нет | A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use mozilla · firefox · CWE-119 | Критическая9,8 | — | 5,2 % | 11 июн. 2018 г. |
37Наблюдать | CVE-2016-1522Эксплойта нет | Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider remozilla · firefox · CWE-119 | Высокая8,8 | — | 8,3 % | 12 февр. 2016 г. |
36Наблюдать | CVE-2016-2799Эксплойта нет | Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Fmozilla · firefox · CWE-119 | Высокая8,8 | — | 4,9 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-1521Эксплойта нет | The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x mozilla · firefox · CWE-119 | Высокая8,8 | — | 4,1 % | 12 февр. 2016 г. |
36Наблюдать | CVE-2016-2796Эксплойта нет | Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before mozilla · firefox · CWE-119 | Высокая8,8 | — | 3,9 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2794Эксплойта нет | The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox mozilla · firefox · CWE-119 | Высокая8,8 | — | 3,5 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-1977Эксплойта нет | The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38mozilla · firefox · CWE-119 | Высокая8,8 | — | 2,9 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2797Эксплойта нет | The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.mozilla · firefox · CWE-119 | Высокая8,8 | — | 2,7 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2793Эксплойта нет | CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers mozilla · firefox · CWE-119 | Высокая8,8 | — | 2,7 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2017-5436Эксплойта нет | An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.debian · debian linux · CWE-787 | Высокая8,8 | — | 2,4 % | 11 июн. 2018 г. |
36Наблюдать | CVE-2016-2798Эксплойта нет | The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bmozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2790Эксплойта нет | The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x beforemozilla · firefox · CWE-19 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2791Эксплойта нет | The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.mozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2792Эксплойта нет | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bemozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2795Эксплойта нет | The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x beformozilla · firefox · CWE-19 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2800Эксплойта нет | The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x bemozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2801Эксплойта нет | The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and mozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2016-2802Эксплойта нет | The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox Emozilla · firefox · CWE-119 | Высокая8,8 | — | 2,3 % | 13 мар. 2016 г. |
36Наблюдать | CVE-2018-7999Эксплойта нет | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, whisil · graphite2 · CWE-476 | Высокая8,8 | — | 2,2 % | 9 мар. 2018 г. |
36Наблюдать | CVE-2017-7774Эксплойта нет | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.sil · graphite2 · CWE-125 | Критическая9,1 | — | 1,4 % | 15 апр. 2019 г. |
35Наблюдать | CVE-2016-1969Эксплойта нет | The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote atmozilla · firefox · CWE-119 | Высокая8,8 | — | 1,7 % | 13 мар. 2016 г. |
35Наблюдать | CVE-2017-7772Эксплойта нет | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.mozilla · firefox · CWE-119 | Высокая8,8 | — | 1,4 % | 12 апр. 2019 г. |
35Наблюдать | CVE-2017-7773Эксплойта нет | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.mozilla · firefox · CWE-119 | Высокая8,8 | — | 1,4 % | 15 апр. 2019 г. |
35Наблюдать | CVE-2017-7777Эксплойта нет | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.mozilla · firefox · CWE-119 | Высокая8,8 | — | 1,2 % | 15 апр. 2019 г. |
33Наблюдать | CVE-2017-7776Эксплойта нет | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.sil · graphite2 · CWE-125 | Высокая8,1 | — | 2,8 % | 15 апр. 2019 г. |
- CVE-2017-777841В плане
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mozilla · firefox11 июн. 2018 г.
- CVE-2016-152237Наблюдать
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider re
ВысокаяCVSS 8,8Эксплойта нетEPSS 8 %mozilla · firefox12 февр. 2016 г.
- CVE-2016-279936Наблюдать
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and F
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-152136Наблюдать
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %mozilla · firefox12 февр. 2016 г.
- CVE-2016-279636Наблюдать
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279436Наблюдать
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-197736Наблюдать
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279736Наблюдать
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279336Наблюдать
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mozilla · firefox13 мар. 2016 г.
- CVE-2017-543636Наблюдать
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %debian · debian linux11 июн. 2018 г.
- CVE-2016-279836Наблюдать
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x b
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279036Наблюдать
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279136Наблюдать
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279236Наблюдать
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-279536Наблюдать
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x befor
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-280036Наблюдать
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x be
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-280136Наблюдать
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2016-280236Наблюдать
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2018-799936Наблюдать
In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, whi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sil · graphite29 мар. 2018 г.
- CVE-2017-777436Наблюдать
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sil · graphite215 апр. 2019 г.
- CVE-2016-196935Наблюдать
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote at
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %mozilla · firefox13 мар. 2016 г.
- CVE-2017-777235Наблюдать
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox12 апр. 2019 г.
- CVE-2017-777335Наблюдать
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox15 апр. 2019 г.
- CVE-2017-777735Наблюдать
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox15 апр. 2019 г.
- CVE-2017-777633Наблюдать
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %sil · graphite215 апр. 2019 г.