Total
                    28 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2017-7778 | 3 Debian, Mozilla, Sil | 5 Debian Linux, Firefox, Firefox Esr and 2 more | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL | 
| A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. | |||||
| CVE-2017-7777 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH | 
| Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | |||||
| CVE-2017-7776 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 5.8 MEDIUM | 8.1 HIGH | 
| Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | |||||
| CVE-2017-7774 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL | 
| Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | |||||
| CVE-2017-7773 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH | 
| Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | |||||
| CVE-2017-7772 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH | 
| Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | |||||
| CVE-2017-7771 | 2 Mozilla, Sil | 2 Firefox, Graphite2 | 2024-11-21 | 5.8 MEDIUM | 8.1 HIGH | 
| Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | |||||
| CVE-2017-5436 | 4 Debian, Mozilla, Redhat and 1 more | 11 Debian Linux, Firefox, Firefox Esr and 8 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH | 
| An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | |||||
