Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-2052

Опубликовано: 25 янв. 2016
Источник: nvd
CVSS3: 7.6
CVSS2: 6.8
EPSS Низкий

Описание

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:harfbuzz_project:harfbuzz:*:*:*:*:*:*:*:*
Версия до 1.0.5 (включая)
Конфигурация 2
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Версия до 47.0.2526.106 (включая)

EPSS

Процентиль: 61%
0.00408
Низкий

7.6 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

redhat
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

CVSS3: 7.6
debian
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used ...

CVSS3: 7.6
github
больше 3 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

fstec
около 10 лет назад

Уязвимости браузера Google Chrome и библиотеки форматирования текста HarfBuzz, позволяющие нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 61%
0.00408
Низкий

7.6 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo