CVEs (95)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+9 moreMay 6, 2026 Feb 8, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreetype+2 moreMay 6, 2026 Feb 8, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possib...Show more |
2Canonical Freetype2Freetype Ubuntu LinuxMay 6, 2026 Mar 18, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of serv...Show more |
Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number...Show more |
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negat...Show more |
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calcu...Show more |
FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handling of an "allocation error" in the bdf_f...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font. |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arb...Show more |
2Freetype Mozilla2Firefox Mobile FreetypeApr 29, 2026 Apr 25, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbi...Show more |