High severity7.5NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-9814
CVE-2017-9814
Description
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugs.freedesktop.org/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00042.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201904-01nvdThird Party Advisory
- lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Envd
News mentions
0No linked articles in our index yet.