Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fontforge HIGH 8.8
CVE-2025-15280

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 7.8
CVE-2025-15277

FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 7.8
CVE-2025-15278

FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 7.8
CVE-2025-15279

FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15271

FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15272

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15273

FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15274

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15275

FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 7.8
CVE-2025-15276

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15269

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge HIGH 8.8
CVE-2025-15270

FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…

Mitigation only
Fix from $1,950 2025-12-31
Fontforge MEDIUM 6.5
CVE-2025-50951

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

Patch available
Fix from $1,600 2025-10-23
Fontforge MEDIUM 6.5
CVE-2025-50949

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

Patch available
Fix from $1,600 2025-10-23
Fontforge HIGH 8.8
CVE-2020-25690

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This fla…

Fix: 20200314+
Fix from $1,950 2021-02-23
Fontforge HIGH 8.8
CVE-2020-5496

FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

No fix yet
Fix from $1,950 2020-01-03
Fontforge CRITICAL 9.8
CVE-2019-15785

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

Fix: after 20190801
Fix from $2,300 2019-08-29
Fontforge HIGH 8.8
CVE-2017-17521

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which mi…

Fix: after 20170731
Fix from $1,950 2017-12-14
Fontforge HIGH 7.8
CVE-2017-11568

FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafte…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11569

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted …

Mitigation only
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11570

FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11571

FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11572

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted ot…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11573

FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted ot…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11574

FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11575

FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a …

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11577

FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Fontforge MEDIUM 5.5
CVE-2017-11576

FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf f…

Patch available
Fix from $1,600 2017-07-23