Sploitus

CVE-2016-2796

1 known exploit for CVE-2016-2796

Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.

Sil graphite2
≤ 1.3.5
Fix
Available
CVSS 3.0
8.8 HIGH
EPSS
3.6% (89th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2016-03-13
CVE-2016-2796 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2016-2796

Proof-of-concept code and exploit modules indexed by Sploitus