Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1194

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.049
EPSS Ranking 88.9%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2009-1194
  • Pango » Pango » Version: Any
    cpe:2.3:a:pango:pango:*
  • Pango » Pango » Version: 1.10
    cpe:2.3:a:pango:pango:1.10
  • Pango » Pango » Version: 1.12
    cpe:2.3:a:pango:pango:1.12
  • Pango » Pango » Version: 1.14
    cpe:2.3:a:pango:pango:1.14
  • Pango » Pango » Version: 1.16
    cpe:2.3:a:pango:pango:1.16
  • Pango » Pango » Version: 1.18
    cpe:2.3:a:pango:pango:1.18
  • Pango » Pango » Version: 1.2
    cpe:2.3:a:pango:pango:1.2
  • Pango » Pango » Version: 1.20
    cpe:2.3:a:pango:pango:1.20
  • Pango » Pango » Version: 1.4
    cpe:2.3:a:pango:pango:1.4
  • Pango » Pango » Version: 1.6
    cpe:2.3:a:pango:pango:1.6
  • Pango » Pango » Version: 1.8
    cpe:2.3:a:pango:pango:1.8


Contact Us

Shodan ® - All rights reserved