CVE-2016-2800: Buffer Overflow
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2800?
CVE-2016-2800 is considered a moderate severity vulnerability that can cause a denial of service due to a buffer over-read.
How do I fix CVE-2016-2800?
To fix CVE-2016-2800, update your version of Mozilla Firefox or Firefox ESR to at least version 45.0 or 38.7 for Firefox ESR.
Which software is affected by CVE-2016-2800?
CVE-2016-2800 affects Mozilla Firefox versions prior to 45.0 and Firefox ESR versions prior to 38.7.
What kind of impact can CVE-2016-2800 have?
CVE-2016-2800 can allow remote attackers to cause a denial of service or potentially other unspecified impacts.
Is CVE-2016-2800 specific to certain operating systems?
CVE-2016-2800 primarily affects Firefox and Firefox ESR, which run on various operating systems including Windows and Linux.