CVE-2016-1522

Description

Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.415

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.1.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.1.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.0.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.1.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.2.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.2.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.0.5Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.1.1Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.2.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.2.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.3.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.4.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.3.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.4.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.5.0Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.5.1Windows
Vulnerabilities CVE-2016-1521,CVE-2016-1522,CVE-2016-1523,CVE-2016-1526 are affected in Mozilla Firefox (x64) 38.5.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 38.6.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.5.0Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.5.1Windows
Vulnerabilities CVE-2016-1521,CVE-2016-1522,CVE-2016-1523,CVE-2016-1526 are affected in Mozilla_Firefox 38.5.2Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 38.6.0Windows
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-1ubuntu1.1_i386.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-1ubuntu1.1_amd64.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-3ubuntu1.1_i386.debLinux
Font rendering engine for Complex Scripts (USN-2902-1) libgraphite2-3_1.2.4-3ubuntu1.1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234