RSS   Vulnerabilities for 'Libcroco'   RSS

2020-05-12
 
CVE-2020-12825

CWE-674
 

 
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

 
2017-06-12
 
CVE-2017-8871

CWE-835
 

 
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

 
 
CVE-2017-8834

CWE-119
 

 
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.

 
2017-04-19
 
CVE-2017-7961

CWE-119
 

 
** DISPUTED ** The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components."

 
 
CVE-2017-7960

CWE-125
 

 
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

 

 >>> Vendor: Gnome 89 Products
Gnumeric
GDM
Gnome libs
Gnome-lokkit
Esound
Gnorpm
Libgtop daemon
Nautilus
Evolution
Bonobo
Gnome-terminal
Gtkhtml
EOG
Balsa
Batalla naval
Gdkpixbuf
GPDF
Libvte4
Libzvt2
Epiphany
Gedit
Networkmanager
Libgda2
DIA
Dwarf http server
Screensaver
Dhcdbd
Libgsf
Libsoup
Gconf
Power manager
Ekiga
Gnome-vfs
Gnome
YELP
GLIB
ORCA
Vinagre
Rhythmbox
Nautilus-python
Evolution-data-server
Gupnp
Gmime
Evince
Gnome-shell
Tomboy
Ifcfg-rh plug-in
Empathy
Update-manager-core
Gdk-pixbuf
Libgdata
At-spi2-atk
Librsvg
Libsocialweb
Gnome-keyring
Gnome display manager
Gnome online accounts
Geary
GCAB
VALA
Byzanz
Eye of gnome
Shotwell
Gtk-vnc
Libcroco
Gnome-session
Libgxps
Librest
Gthumb
Seahorse
GVFS
Gnome-desktop
Evolution-ews
Network manager vpnc
Gnome-system-log
Gnome-font-viewer
Gnome keyring
Evolution data server
File-roller
Glib-networking
Gnome-autoar
Libgrss
Libgda
Libgfbgraph
Grilo
Evolution-rss
Libzapojit
Ocrfeeder
Caribou


Copyright 2024, cxsecurity.com

 

Back to Top