Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2052

Опубликовано: 24 янв. 2016
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7harfbuzzWill not fix
Red Hat Enterprise Linux 6 Supplementarychromium-browserFixedRHSA-2016:007227.01.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1301553chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6

EPSS

Процентиль: 61%
0.00408
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

CVSS3: 7.6
nvd
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

CVSS3: 7.6
debian
около 10 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used ...

CVSS3: 7.6
github
больше 3 лет назад

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

fstec
около 10 лет назад

Уязвимости браузера Google Chrome и библиотеки форматирования текста HarfBuzz, позволяющие нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 61%
0.00408
Низкий

5.1 Medium

CVSS2