Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31146
HistoryJul 06, 2021 - 9:08 a.m.

Arbitrary Code Execution

2021-07-0609:08:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.008 Low

EPSS

Percentile

82.2%

harfbuzz is vulnerable to arbitrary code execution. A buffer over-read resulting from an inverted length check in hb-ot-font.cc allows an attacker to crash the application and potentially obtain arbitrary code execution.

CPENameOperatorVersion
harfbuzzle0.9.41.1
harfbuzzle0.9.41.1