VendorsHarfbuzz Projectharfbuzzany version
Vulnerabilities

Harfbuzz Project Harfbuzz any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-56732
HarfBuzz heap-buffer-overflow on hb_cairo_glyphs_from_buffer
Published 2024-12-27 · Analyzed
9.3EPSS 0.007
CVE-2015-8947
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Published 2016-07-19 · Modified
7.6EPSS 0.025
CVE-2016-2052
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Published 2016-01-25 · Modified
7.6EPSS 0.010
CVE-2023-25193
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Published 2023-02-04 · Modified
7.5EPSS 0.018
CVE-2015-9274
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
Published 2018-11-15 · Modified
6.5EPSS 0.015
CVE-2026-22693
Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS
Published 2026-01-10 · Analyzed
5.3EPSS 0.004