VYPR

Stb Truetype.h

by Nothings

CVEs (12)

  • CVE-2020-6623HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

  • CVE-2020-6622HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.

  • CVE-2020-6621HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.

  • CVE-2020-6620HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.

  • CVE-2020-6619HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

  • CVE-2020-6618HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.

  • CVE-2020-6617HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.01

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

  • CVE-2022-25514HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.

  • CVE-2022-25516MedMar 17, 2022
    risk 0.42cvss 6.5epss 0.01

    stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.

  • CVE-2022-25515MedMar 17, 2022
    risk 0.42cvss 6.5epss 0.01

    stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.

  • CVE-2026-5315MedApr 2, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The…

  • CVE-2026-5314MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The…