Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sil

First CVE: Feb 13, 2016Active for: 10 yearsTotal CVEs: 28
59.2
VTI Score
TOP TARGET

Sil maintains a narrowly scoped vulnerability footprint centered on the Graphite2 font-rendering library, a component embedded in document processors, browsers, and messaging applications across many platforms despite the vendor's small product count. The recurring exposure reflects the inherent complexity of parsing untrusted font data: vulnerabilities cluster around memory-safety weaknesses including buffer-boundary violations, out-of-bounds reads and writes, and sensitive-information exposure. The moderate severity profile typical of memory-corruption flaws in parsing libraries means that defenders should prioritize tracking font-rendering updates as part of their broader application and browser patch cycles, particularly for systems that process documents from untrusted sources. Live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
9.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sil over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2016
10 years ago
Most Recent CVE
Apr 15, 2019
2,657 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7774CRITICAL
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
Apr 15, 20199.130NONO
CVE-2016-2800HIGH
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to ca
Mar 13, 20168.829NONO
CVE-2016-2799HIGH
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remo
Mar 13, 20168.829NONO
CVE-2017-7777HIGH
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
Apr 15, 20198.828NONO
CVE-2017-7773HIGH
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
Apr 15, 20198.828NONO
CVE-2017-7772HIGH
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
Apr 12, 20198.828NONO
CVE-2016-1522HIGH
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check,
Feb 13, 20168.828NONO
CVE-2016-1521HIGH
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certa
Feb 13, 20168.828NONO
CVE-2017-7776HIGH
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
Apr 15, 20198.127NONO
CVE-2017-7778CRITICAL
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues we
Jun 11, 20189.827NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
89%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (7.1%)
Unknown0 (0.0%)
Required26 (92.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None28 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sil.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sil — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sil's Products

View all 3 CNAs →

Top CWEs