VYPR

Cairo

by Cairographics

CVEs (4)

  • CVE-2017-9814HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.00

    cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.

  • CVE-2016-3190HigApr 21, 2016
    risk 0.49cvss 7.5epss 0.01

    The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a negative span length.

  • CVE-2017-7475MedMay 19, 2017
    risk 0.36cvss 5.5epss 0.00

    Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

  • CVE-2014-5116Jul 29, 2014
    risk 0.03cvss epss 0.06

    The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.