Show filters
43 Total Results
Displaying 11-20 of 43
Sort by:
Attacker Value
Unknown

CVE-2022-4728

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. VDB-216742 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2017-18638

Disclosure Date: October 11, 2019 (last updated November 27, 2024)
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.
Attacker Value
Unknown

CVE-2017-7771

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
0
Attacker Value
Unknown

CVE-2017-7774

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
0
Attacker Value
Unknown

CVE-2017-7773

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
0
Attacker Value
Unknown

CVE-2017-7777

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
0
Attacker Value
Unknown

CVE-2017-7776

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
0
Attacker Value
Unknown

CVE-2017-7772

Disclosure Date: April 12, 2019 (last updated November 27, 2024)
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
0
Attacker Value
Unknown

CVE-2017-5436

Disclosure Date: June 11, 2018 (last updated October 22, 2024)
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown

CVE-2017-7778

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
0