VYPR
Critical severity9.8NVD Advisory· Published Jun 7, 2016· Updated Jun 17, 2026

CVE-2014-9746

CVE-2014-9746

Description

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • FreeType/Freetype2 versions
    cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*range: <=2.5.3
    • (no CPE)range: <2.5.4
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.