CVE-2014-5116: Cairographics Cairo

Medium severity, CVSS 5.0. EPSS: 7.6% chance of exploitation in the next 30 days.

The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.

Affected products

Published 2014-07-29. Last modified 2026-06-17.