VYPR
Unrated severityNVD Advisory· Published May 17, 2007· Updated Apr 23, 2026

CVE-2007-2754

CVE-2007-2754

Description

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

60

News mentions

0

No linked articles in our index yet.