CVE-2024-56732
Severity CVSS v4.0:
CRITICAL
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
27/12/2024
Last modified:
28/12/2024
Description
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
8.80
Severity 3.x
HIGH