📦

libgxps

Vendor: gnome

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 20 Total Indexed
Avg. EPSS 2.02% Exploit Prob.
Latest CVE CVE-2018-10767 May 06

Security Vulnerability Index

Page 1 / 2
6.5 CVSS

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.

EPSS: 2.27%
6.5 CVSS

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

EPSS: 2.26%
7.5 CVSS

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

EPSS: 1.53%