6.8

CVE-2009-1194

Exploit

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.

Data is provided by the National Vulnerability Database (NVD)
PangoPango Version <= 1.22
PangoPango Version1.2
PangoPango Version1.4
PangoPango Version1.6
PangoPango Version1.8
PangoPango Version1.10
PangoPango Version1.12
PangoPango Version1.14
PangoPango Version1.16
PangoPango Version1.18
PangoPango Version1.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.85% 0.885
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P