9.8
CVSSv3

CVE-2016-10328

Published: 14/04/2017 Updated: 26/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

FreeType 2 prior to 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freetype freetype

oracle outside in technology 8.5.4

Vendor Advisories

FreeType could be made to crash or run programs if it opened a specially crafted font file ...
FreeType 2 before 2016-12-16 (271) has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparsec ...