Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla HarfBuzz hb-buffer.c hb_buffer_ensure函数拒绝服务漏洞
Vulnerability Description
在Pango 1.28.3,Firefox和其他产品中使用的HarfBuzz中的hb-buffer.c中的hb_buffer_ensure函数没有正确验证内存分配的返回值。远程攻击者可以借助能够触发不正确索引使用的特制OpenType字体数据导致拒绝服务(空指针解引用和应用程序崩溃)或者可能执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A