VYPR
Unrated severityNVD Advisory· Published May 17, 2007· Updated Jun 16, 2026

CVE-2007-2754

CVE-2007-2754

Description

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • FreeType/Freetype2 versions
    cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*range: <=2.3.4
    • (no CPE)range: <=2.3.4

Patches

Vulnerability mechanics

References

60

News mentions

0

No linked articles in our index yet.