CVE-2015-8947: Harfbuzz Project Harfbuzz
High severity, CVSS 7.6. EPSS: 2.6% chance of exploitation in the next 30 days.
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Affected products
- Harfbuzz Project Harfbuzz: up to and including 1.0.4
Published 2016-07-19. Last modified 2026-06-17.