VYPR
Medium severity5.5NVD Advisory· Published Apr 19, 2017· Updated May 13, 2026

CVE-2017-7960

CVE-2017-7960

Description

The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

Affected products

2
  • cpe:2.3:a:gnome:libcroco:0.6.11:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gnome:libcroco:0.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:gnome:libcroco:0.6.12:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.