Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freetype MEDIUM 5.3
CVE-2026-23865

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bo…

Fix: after 2.14.1
Fix from $1,600 2026-03-02
Freetype MEDIUM 6.2
CVE-2025-23022

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

No fix yet
Fix from $1,600 2025-01-10
Freetype CRITICAL 9.8
CVE-2015-9290

In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of…

Fix: 2.6.1+
Fix from $2,300 2019-07-30
Freetype CRITICAL 9.8
CVE-2017-8287

FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in ps…

Fix: after 2.7.1
Fix from $2,300 2017-04-27
Freetype CRITICAL 9.8
CVE-2016-10328

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse…

Fix: after 2.7
Fix from $2,300 2017-04-14
Freetype CRITICAL 9.8
CVE-2017-7857

FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgx…

Fix: 2.8+
Fix from $2,300 2017-04-14
Freetype CRITICAL 9.8
CVE-2017-7858

FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function i…

Fix: after 2.7.1
Fix from $2,300 2017-04-14
Freetype CRITICAL 9.8
CVE-2017-7864

FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttob…

Fix: after 2.7.1
Fix from $2,300 2017-04-14
Freetype HIGH 7.5
CVE-2014-2240EPSS 6%

Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of…

Fix: after 2.5.2
Fix from $1,950 2014-03-12
Freetype HIGH 9.3
CVE-2011-0226EPSS 7%

Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and o…

Fix: after 4.2.8
Fix from $1,950 2011-07-19
Freetype HIGH 9.3
CVE-2010-3311EPSS 7%

Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of servic…

Fix: after 2.3.12
Fix from $1,950 2011-01-07
Freetype MEDIUM 6.8
CVE-2010-3855EPSS 5%

Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial…

Fix: after 2.4.3
Fix from $1,600 2010-11-26
Freetype MEDIUM 6.8
CVE-2010-3814

Heap-based buffer overflow in the Ins_SHZ function in ttinterp.c in FreeType 2.4.3 and earlier allows remote attackers to execute arbitrary code or c…

Fix: after 2.4.3
Fix from $1,600 2010-11-26
Freetype MEDIUM 5.0
CVE-2010-3054

Unspecified vulnerability in FreeType 2.3.9, and other versions before 2.4.2, allows remote attackers to cause a denial of service via vectors involv…

Mitigation only
Fix from $1,600 2010-08-19
Freetype HIGH 7.5
CVE-2008-1806

Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values wit…

Patch available
Fix from $1,950 2008-06-16
Freetype HIGH 7.5
CVE-2008-1807

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PF…

Mitigation only
Fix from $1,950 2008-06-16
Freetype HIGH 7.5
CVE-2008-1808

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer…

Patch available
Fix from $1,950 2008-06-16
Freetype HIGH 7.5
CVE-2007-3506

The ft_bitmap_assure_buffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent attackers to cause a denial of service and poss…

Fix: after 2.3.3
Fix from $1,950 2007-07-02
Freetype MEDIUM 6.8
CVE-2007-2754EPSS 6%

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF…

Fix: after 2.3.4
Fix from $1,600 2007-05-17
Freetype HIGH 7.5
CVE-2006-3467

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafte…

Fix: after 2.1
Fix from $1,950 2006-07-21
Freetype HIGH 7.5
CVE-2006-1861

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…

Patch available
Fix from $1,950 2006-05-23
Freetype MEDIUM 5.0
CVE-2006-0747EPSS 12%

Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue valu…

Fix: after 2.1
Fix from $1,600 2006-05-23