Critical severity9.8NVD Advisory· Published Jun 7, 2016· Updated May 6, 2026
CVE-2014-9746
CVE-2014-9746
Description
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.
Affected products
3cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/nvd
- www.debian.org/security/2015/dsa-3370nvd
- www.openwall.com/lists/oss-security/2015/09/11/4nvd
- www.openwall.com/lists/oss-security/2015/09/25/4nvd
- www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlnvd
- savannah.nongnu.org/bugs/nvd
News mentions
0No linked articles in our index yet.