ALT-PU-2016-1478-1
Package libgraphite2 updated to version 1.3.8-alt1 for branch sisyphus in task 164508.
Closed vulnerabilities
BDU:2016-00718
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00719
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00720
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00721
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00722
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00723
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00724
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00725
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00726
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00727
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00728
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00729
Уязвимость браузеров Firefox ESR и Firefox, программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00730
Уязвимость программного средства рендеринга Graphite 2, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00741
Уязвимость программного средства рендеринга Graphite 2, браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00749
Уязвимость программного средства рендеринга Graphite 2, браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
Modified: 2024-11-21
CVE-2016-1969
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Modified: 2024-11-21
CVE-2016-1977
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248876
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248876
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2790
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243464
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243464
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2791
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243473
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243473
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2792
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243482
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243482
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2793
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243513
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243513
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2794
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243526
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243526
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2795
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243597
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243597
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2796
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243816
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243816
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2797
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243823
- https://bugzilla.mozilla.org/show_bug.cgi?id=1243823
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2798
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248805
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248805
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2799
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249081
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249081
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2800
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249338
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249338
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2801
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249920
- https://bugzilla.mozilla.org/show_bug.cgi?id=1249920
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63
Modified: 2024-11-21
CVE-2016-2802
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
- SUSE-SU-2016:0727
- SUSE-SU-2016:0727
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0731
- openSUSE-SU-2016:0733
- openSUSE-SU-2016:0733
- SUSE-SU-2016:0777
- SUSE-SU-2016:0777
- SUSE-SU-2016:0820
- SUSE-SU-2016:0820
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0876
- openSUSE-SU-2016:0894
- openSUSE-SU-2016:0894
- SUSE-SU-2016:0909
- SUSE-SU-2016:0909
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1767
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1769
- openSUSE-SU-2016:1778
- openSUSE-SU-2016:1778
- DSA-3510
- DSA-3510
- DSA-3515
- DSA-3515
- DSA-3520
- DSA-3520
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-37.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 84222
- 84222
- 1035215
- 1035215
- USN-2917-1
- USN-2917-1
- USN-2917-2
- USN-2917-2
- USN-2917-3
- USN-2917-3
- USN-2927-1
- USN-2927-1
- USN-2934-1
- USN-2934-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248804
- https://bugzilla.mozilla.org/show_bug.cgi?id=1248804
- GLSA-201605-06
- GLSA-201605-06
- GLSA-201701-63
- GLSA-201701-63