CVE-2016-2794

high
Published 2016-03-13 · Modified 2026-05-06
CVSS v3
8.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
VIR risk
8.8

Description

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debiansidfixed45.0-1
debian debianbookwormfixed45.0esr-1
debian debianbullseyefixed45.0esr-1
debian debianforkyfixed45.0esr-1
debian debiantrixiefixed45.0esr-1
suse suse42.1affected
suse suse13.1affected
suse suse13.2affected

Application impact

VendorProductVersionsFixed
mozilla mozillafirefox{"endIncluding":"44.0.2"}
mozilla mozillafirefox38.0
mozilla mozillafirefox38.0.1
mozilla mozillafirefox38.0.5
mozilla mozillafirefox38.1.0
mozilla mozillafirefox38.1.1
mozilla mozillafirefox38.2.0
mozilla mozillafirefox38.2.1
mozilla mozillafirefox38.3.0
mozilla mozillafirefox38.4.0
mozilla mozillafirefox38.5.0
mozilla mozillafirefox38.5.1
mozilla mozillafirefox38.6.0
mozilla mozillafirefox38.6.1
silgraphite2{"endIncluding":"1.3.5"}

References

CWEs

CWE-119

💬 Discuss CVE-2016-2794 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.