Lucene search

K
cveMitreCVE-2024-25081
HistoryFeb 26, 2024 - 4:27 p.m.

CVE-2024-25081

2024-02-2616:27:58
CWE-77
mitre
web.nvd.nist.gov
4267
cve-2024-25081
splinefont
fontforge
command injection
nvd

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

8.7

Confidence

High

EPSS

0

Percentile

15.5%

Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

CVSS3

4.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

8.7

Confidence

High

EPSS

0

Percentile

15.5%