Lucene search

K

Freetype Security Vulnerabilities

cve
cve

CVE-2022-27404

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function...

9.8CVSS

9.7AI Score

0.009EPSS

2022-04-22 02:15 PM
187
4
cve
cve

CVE-2022-27405

FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function...

7.5CVSS

8.5AI Score

0.003EPSS

2022-04-22 02:15 PM
184
5
cve
cve

CVE-2022-27406

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function...

7.5CVSS

8.6AI Score

0.004EPSS

2022-04-22 02:15 PM
224
3
cve
cve

CVE-2020-15999

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

6.5CVSS

7.1AI Score

0.026EPSS

2020-11-03 03:15 AM
1812
In Wild
22
cve
cve

CVE-2015-9290

In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to...

9.8CVSS

7.7AI Score

0.006EPSS

2019-07-30 01:15 PM
165
cve
cve

CVE-2006-1861

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in...

7.7AI Score

0.137EPSS

2006-05-23 10:06 AM
45
cve
cve

CVE-2015-9383

FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in...

6.5CVSS

6.5AI Score

0.004EPSS

2019-09-03 05:15 AM
219
cve
cve

CVE-2012-1126

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF...

7.7AI Score

0.244EPSS

2012-04-25 10:10 AM
37
cve
cve

CVE-2010-3855

Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX...

6.4AI Score

0.174EPSS

2010-11-26 08:00 PM
45
cve
cve

CVE-2010-3311

Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer...

8.2AI Score

0.513EPSS

2011-01-07 11:00 PM
41
cve
cve

CVE-2007-2754

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer...

8AI Score

0.622EPSS

2007-05-17 10:30 PM
44
cve
cve

CVE-2006-3467

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of...

7.9AI Score

0.168EPSS

2006-07-21 02:03 PM
49
cve
cve

CVE-2012-1130

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
34
cve
cve

CVE-2012-1139

Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
27
cve
cve

CVE-2012-1143

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted...

6.1AI Score

0.053EPSS

2012-04-25 10:10 AM
30
cve
cve

CVE-2012-1141

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
40
cve
cve

CVE-2012-1137

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted header in a BDF...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
34
cve
cve

CVE-2012-1144

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
39
cve
cve

CVE-2012-1140

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font...

7.7AI Score

0.047EPSS

2012-04-25 10:10 AM
38
cve
cve

CVE-2012-1136

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an...

7.8AI Score

0.055EPSS

2012-04-25 10:10 AM
37
cve
cve

CVE-2012-1134

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1...

7.8AI Score

0.055EPSS

2012-04-25 10:10 AM
42
cve
cve

CVE-2012-1127

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
30
cve
cve

CVE-2012-1131

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, on 64-bit platforms allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors related to the cell table of a...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
37
cve
cve

CVE-2012-1142

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a...

7.8AI Score

0.055EPSS

2012-04-25 10:10 AM
38
cve
cve

CVE-2012-1132

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1...

7.7AI Score

0.052EPSS

2012-04-25 10:10 AM
39
cve
cve

CVE-2010-2500

Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font...

9AI Score

0.016EPSS

2010-08-19 06:00 PM
43
5
cve
cve

CVE-2010-2519

Heap-based buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted length value in a POST fragment header in a font...

9AI Score

0.005EPSS

2010-08-19 06:00 PM
45
3
cve
cve

CVE-2010-2808

Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN)...

9.8AI Score

0.018EPSS

2010-08-19 06:00 PM
49
cve
cve

CVE-2010-2806

Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based....

9.8AI Score

0.004EPSS

2010-08-19 06:00 PM
47
cve
cve

CVE-2015-9382

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face...

6.5CVSS

6.6AI Score

0.006EPSS

2019-09-03 05:15 AM
188
cve
cve

CVE-2015-9381

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in...

8.8CVSS

7.2AI Score

0.013EPSS

2019-09-03 05:15 AM
198
cve
cve

CVE-2018-6942

An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font...

6.5CVSS

6.1AI Score

0.003EPSS

2018-02-13 05:29 AM
147
cve
cve

CVE-2017-8287

FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in...

9.8CVSS

9.5AI Score

0.009EPSS

2017-04-27 12:59 AM
130
cve
cve

CVE-2017-8105

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in...

9.8CVSS

9.5AI Score

0.012EPSS

2017-04-24 06:59 PM
133
cve
cve

CVE-2017-7858

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in...

9.8CVSS

9.3AI Score

0.014EPSS

2017-04-14 04:59 AM
34
4
cve
cve

CVE-2017-7857

FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in...

9.8CVSS

9.5AI Score

0.009EPSS

2017-04-14 04:59 AM
38
4
cve
cve

CVE-2017-7864

FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in...

9.8CVSS

9.5AI Score

0.009EPSS

2017-04-14 04:59 AM
56
cve
cve

CVE-2016-10328

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in...

9.8CVSS

9.5AI Score

0.009EPSS

2017-04-14 04:59 AM
60
4
cve
cve

CVE-2016-10244

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted...

7.8CVSS

7.2AI Score

0.011EPSS

2017-03-06 06:59 AM
117
cve
cve

CVE-2014-9747

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42...

7.5CVSS

6.5AI Score

0.017EPSS

2016-06-07 02:06 PM
51
cve
cve

CVE-2014-9746

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote...

9.8CVSS

9.5AI Score

0.025EPSS

2016-06-07 02:06 PM
37
cve
cve

CVE-2014-9745

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by...

6.2AI Score

0.066EPSS

2015-09-14 08:59 PM
53
cve
cve

CVE-2014-9675

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF...

7.5AI Score

0.004EPSS

2015-02-08 11:59 AM
59
cve
cve

CVE-2014-9674

The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified...

8AI Score

0.025EPSS

2015-02-08 11:59 AM
62
cve
cve

CVE-2014-9673

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac...

7.9AI Score

0.029EPSS

2015-02-08 11:59 AM
65
cve
cve

CVE-2014-9672

Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font...

7.1AI Score

0.03EPSS

2015-02-08 11:59 AM
40
cve
cve

CVE-2014-9671

Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly...

7AI Score

0.025EPSS

2015-02-08 11:59 AM
60
cve
cve

CVE-2014-9670

Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first....

7.1AI Score

0.022EPSS

2015-02-08 11:59 AM
54
cve
cve

CVE-2014-9669

Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT...

7.8AI Score

0.012EPSS

2015-02-08 11:59 AM
63
cve
cve

CVE-2014-9668

The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact...

8AI Score

0.037EPSS

2015-02-08 11:59 AM
35
Total number of security vulnerabilities92