CVE Tools

Cairographics

3 CVEs tracked since 2014. Since Jul 2014, none of them reached CISA KEV.

Cairographics CVEs per month

Jul 2014 to Feb 2017. Point at a month, or focus the strip and use the arrow keys.
Cairographics CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0710
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-0410
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-0210

Products

The products that kept showing up in Cairographics's monthly top three, with their CVEs summed over those months.

  1. Cairo33 months

Latest CVEs

The 11 most recently published vulnerabilities affecting Cairographics.

  1. CVE-2025-50422Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.2.9
  2. CVE-2020-35492A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convin...7.8
  3. CVE-2019-6462An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.6.5
  4. CVE-2019-6461An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.6.5
  5. CVE-2018-19876cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): inval...6.5
  6. CVE-2018-18064cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the genera...6.5
  7. CVE-2017-9814cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.7.5
  8. CVE-2017-7475Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.5.5
  9. CVE-2016-9082Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.5.5
  10. CVE-2016-3190The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a n...7.5
  11. CVE-2014-5116The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.5.0

The record

Peak rank
#108 in Jul 2014
Busiest month shown
Jul 2014, 1 CVEs
Months with a KEV entry
0 since Jul 2014
Monthly snapshots
3 since 2014
Cairographics's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store