Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18064

Опубликовано: 08 окт. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cairographics:cairo:*:*:*:*:*:*:*:*
Версия до 1.15.14 (включая)

EPSS

Процентиль: 66%
0.0051
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

CVSS3: 6.3
redhat
больше 7 лет назад

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

CVSS3: 6.5
debian
больше 7 лет назад

cairo through 1.15.14 has an out-of-bounds stack-memory write during p ...

CVSS3: 6.5
github
больше 3 лет назад

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

EPSS

Процентиль: 66%
0.0051
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-787