Pango
2 CVEs tracked since 2009. Since May 2009, none of them reached CISA KEV.
Pango CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2009-05 | 1 | 0 |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | null or fewer | |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | null or fewer | |
| 2010-05 | null or fewer | |
| 2010-06 | null or fewer | |
| 2010-07 | null or fewer | |
| 2010-08 | null or fewer | |
| 2010-09 | null or fewer | |
| 2010-10 | null or fewer | |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | 1 | 0 |
Products
The products that kept showing up in Pango's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Pango.
- CVE-2020-17365Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. ...7.8
- CVE-2020-12828An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path w...9.8
- CVE-2011-0020Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-ass...7.6
- CVE-2009-1194Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possi...6.8
The record
- Peak rank
- #119 in Jan 2011
- Busiest month shown
- May 2009, 1 CVEs
- Months with a KEV entry
- 0 since May 2009
- Monthly snapshots
- 2 since 2009