Harfbuzz Project

Harfbuzz

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Published 04.02.2023 20:15:08
  • Last modified 25.03.2025 21:15:41

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Exploit
  • EPSS 0.07%
  • Published 23.06.2022 17:15:14
  • Last modified 21.11.2024 07:07:30

An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

Exploit
  • EPSS 0.77%
  • Published 01.01.2022 01:15:08
  • Last modified 21.11.2024 06:33:17

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

  • EPSS 1.05%
  • Published 15.11.2018 06:29:00
  • Last modified 21.11.2024 02:40:13

HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layo...

  • EPSS 0.48%
  • Published 19.07.2016 10:59:00
  • Last modified 12.04.2025 10:46:40

hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.

  • EPSS 0.47%
  • Published 25.01.2016 11:59:10
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting ...