High severity8.8NVD Advisory· Published Feb 13, 2016· Updated Jun 17, 2026
CVE-2016-1522
CVE-2016-1522
Description
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.6.0:*:*:*:*:*:*:*
- (no CPE)range: <43.0
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
- Range: =1.2.4
Patches
Vulnerability mechanics
References
15- blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.htmlnvdExploitThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2016-February/177520.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2016-May/184623.htmlnvdThird Party Advisory
- www.debian.org/security/2016/dsa-3479nvdThird Party Advisory
- www.mozilla.org/security/announce/2016/mfsa2016-14.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-03/msg00058.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0197.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0258.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0594.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlnvd
- www.securityfocus.com/bid/82991nvd
- www.ubuntu.com/usn/USN-2902-1nvd
- security.gentoo.org/glsa/201701-35nvd
- security.gentoo.org/glsa/201701-63nvd
News mentions
0No linked articles in our index yet.