Harfbuzz Project Harfbuzz 0.9.13

CPE Details

Harfbuzz Project Harfbuzz 0.9.13
0.9.13
2019-09-25
12h31 +00:00
2019-09-25
12h31 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:harfbuzz_project:harfbuzz:0.9.13:*:*:*:*:*:*:*

Informations

Vendor

harfbuzz_project

Product

harfbuzz

Version

0.9.13

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-25193 2023-02-04 00h00 +00:00 hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
7.5
Haute
CVE-2015-9274 2018-11-15 04h00 +00:00 HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
6.5
Moyen
CVE-2015-8947 2016-07-19 08h00 +00:00 hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
7.6
Haute
CVE-2016-2052 2016-01-25 10h00 +00:00 Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
7.6
Haute