Sil maintains a narrowly scoped vulnerability footprint centered on the Graphite2 font-rendering library, a component embedded in document processors, browsers, and messaging applications across many platforms despite the vendor's small product count. The recurring exposure reflects the inherent complexity of parsing untrusted font data: vulnerabilities cluster around memory-safety weaknesses including buffer-boundary violations, out-of-bounds reads and writes, and sensitive-information exposure. The moderate severity profile typical of memory-corruption flaws in parsing libraries means that defenders should prioritize tracking font-rendering updates as part of their broader application and browser patch cycles, particularly for systems that process documents from untrusted sources. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sil over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7774CRITICAL Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | Apr 15, 2019 | 9.1 | 30 | NO | NO |
CVE-2016-2800HIGH The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to ca | Mar 13, 2016 | 8.8 | 29 | NO | NO |
CVE-2016-2799HIGH Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remo | Mar 13, 2016 | 8.8 | 29 | NO | NO |
CVE-2017-7777HIGH Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | Apr 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-7773HIGH Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | Apr 15, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-7772HIGH Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | Apr 12, 2019 | 8.8 | 28 | NO | NO |
CVE-2016-1522HIGH Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, | Feb 13, 2016 | 8.8 | 28 | NO | NO |
CVE-2016-1521HIGH The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certa | Feb 13, 2016 | 8.8 | 28 | NO | NO |
CVE-2017-7776HIGH Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | Apr 15, 2019 | 8.1 | 27 | NO | NO |
CVE-2017-7778CRITICAL A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues we | Jun 11, 2018 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sil.
Media articles that mention a CVE ID that affects a product developed by Sil — matched by CVE ID, not by vendor name.