VDB
CVE-2011-3193
CVE-2011-3193
PUBLISHED
Reported by redhat · Published June 16, 2012
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a |
Timeline
- Jun 16, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 46371 third-party-advisoryx_refsource_SECUNIA
- x_refsource_MISC
- USN-1504-1 vendor-advisoryx_refsource_UBUNTU
- [oss-security] 20120824 Re: CVE request: libqt4: two memory issues mailing-listx_refsource_MLIST
- openSUSE-SU-2011:1119 vendor-advisoryx_refsource_SUSE
- 41537 third-party-advisoryx_refsource_SECUNIA
- 46410 third-party-advisoryx_refsource_SECUNIA
- RHSA-2011:1327 vendor-advisoryx_refsource_REDHAT
- RHSA-2011:1325 vendor-advisoryx_refsource_REDHAT
- [oss-security] 20120822 CVE request: libqt4: two memory issues mailing-listx_refsource_MLIST
- 46128 third-party-advisoryx_refsource_SECUNIA
- RHSA-2011:1324 vendor-advisoryx_refsource_REDHAT
- [oss-security] 20120825 Re: CVE request: libqt4: two memory issues mailing-listx_refsource_MLIST
- 49895 third-party-advisoryx_refsource_SECUNIA
- 46117 third-party-advisoryx_refsource_SECUNIA
- RHSA-2011:1326 vendor-advisoryx_refsource_REDHAT
- 46119 third-party-advisoryx_refsource_SECUNIA
- 49723 vdb-entryx_refsource_BID
- x_refsource_MISC
- RHSA-2011:1323 vendor-advisoryx_refsource_REDHAT
…and 8 more