Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
freetype vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-1806
Integer overflow in FreeType2 prior to 2.3.6 allows context-dependent malicious users to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.
Freetype Freetype 2.3.4
Freetype Freetype 2.3.5
Freetype Freetype 1.3.1
Freetype Freetype 2.3.3
NA
CVE-2008-1807
FreeType2 prior to 2.3.6 allow context-dependent malicious users to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.
Freetype Freetype 1.3.1
Freetype Freetype 2.3.5
Freetype Freetype 2.3.3
Freetype Freetype 2.3.4
NA
CVE-2014-2241
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType prior to 2.5.3 do not properly check if a subroutine exists, which allows remote malicious users to cause a denial of service (assertion failure), as demonstrated by a crafte...
Freetype Freetype 2.5
Freetype Freetype 2.5.1
Freetype Freetype
Canonical Ubuntu Linux 13.10
NA
CVE-2011-0226
Integer signedness error in psaux/t1decode.c in FreeType prior to 2.4.6, as used in CoreGraphics in Apple iOS prior to 4.2.9 and 4.3.x prior to 4.3.4 and other products, allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption and ap...
Freetype Freetype 2.4.3
Freetype Freetype 2.4.2
Freetype Freetype 2.3.8
Freetype Freetype 2.3.7
Freetype Freetype 2.3.0
Freetype Freetype 2.2.1
Freetype Freetype 2.4.1
Freetype Freetype 2.4.0
Freetype Freetype 2.3.6
Freetype Freetype 2.3.5
Freetype Freetype 2.2.10
Freetype Freetype
Freetype Freetype 2.3.9
Freetype Freetype 2.3.10
Freetype Freetype 2.3.4
Freetype Freetype 2.3.3
Freetype Freetype 2.4.4
Freetype Freetype 2.3.11
Freetype Freetype 2.3.12
Freetype Freetype 2.3.2
Freetype Freetype 2.3.1
Apple Iphone Os 4.0
9.8
CVSSv3
CVE-2017-7857
FreeType 2 prior to 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
Freetype Freetype
9.8
CVSSv3
CVE-2017-7858
FreeType 2 prior to 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
Freetype Freetype
9.8
CVSSv3
CVE-2017-7864
FreeType 2 prior to 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
Freetype Freetype
NA
CVE-2007-2754
Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and previous versions might allow remote malicious users to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.
Freetype Freetype
NA
CVE-2006-3467
Integer overflow in FreeType prior to 2.2 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PCF file, as demonstrated by the Red Hat bad1.pcf test file, due to a partial fix of CVE-2006-1861.
Freetype Freetype
NA
CVE-2007-3506
The ft_bitmap_assure_buffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent malicious users to cause a denial of service and possibly execute arbitrary code via unspecified vectors involving bitmap fonts, related to a "memory buffer overwrite bug.&q...
Freetype Freetype
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
race condition
CVE-2024-4249
CVE-2024-4244
CVE-2023-20198
TCP
CVE-2022-48648
CVE-2022-48636
CVE-2024-21345
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »