CVE-2016-1709 describes a heap-based buffer overflow in the ByteArray::Get method within Google sfntly, impacting Google Chrome versions prior to 52.0.2743.82. This vulnerability allows remote attackers to trigger a denial of service or potentially achieve other unspecified impacts by providing a specially crafted SFNT font. With a CVSS score of 8.8 (High), it presents a significant risk due to its network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability garnered moderate community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:google:sfntly:-:*:*:*:*:*:*:* | ||
<= 51.0.2704.106CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.