VYPR

Fontforge

by Fontforge

Source repositories

CVEs (33)

  • CVE-2017-11573HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11572HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11571HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11570HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11569HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11568HigJul 23, 2017
    risk 0.51cvss 7.8epss 0.01

    FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.

  • CVE-2017-11576MedJul 23, 2017
    risk 0.36cvss 5.5epss 0.01

    FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.

  • CVE-2010-4259Dec 7, 2010
    risk 0.04cvss epss 0.11

    Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_REGISTRY header in a BDF font file.

  • CVE-2025-50951MedOct 23, 2025
    risk 0.00cvss 6.5epss 0.00

    FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

  • CVE-2025-50949MedOct 23, 2025
    risk 0.00cvss 6.5epss 0.00

    FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

  • CVE-2024-25082MedFeb 26, 2024
    risk 0.00cvss 6.5epss 0.02

    Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

  • CVE-2024-25081MedFeb 26, 2024
    risk 0.00cvss 4.2epss 0.01

    Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

  • CVE-2019-15785CriAug 29, 2019
    risk 0.00cvss 9.8epss 0.03

    FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

Page 2 of 2