CVE-2016-1521: Debian Linux
High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fedoraproject Fedora: version 22 only; version 23 only
- Mozilla Firefox: up to and including 42.0; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only; version 38.1.1 only; version 38.2.0 only; …
- Mozilla Thunderbird: up to and including 38.5.1
- Sil GRAPHITE2: up to and including 1.2.4
Published 2016-02-13. Last modified 2026-06-17.