Vulnerabilities > Freetype > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-04-22 CVE-2022-27404 Out-of-bounds Write vulnerability in multiple products
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
network
low complexity
freetype fedoraproject CWE-787
critical
9.8
2019-07-30 CVE-2015-9290 Out-of-bounds Read vulnerability in Freetype
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
network
low complexity
freetype CWE-125
critical
9.8
2017-04-14 CVE-2017-7858 Out-of-bounds Write vulnerability in Freetype
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
network
low complexity
freetype CWE-787
critical
9.8
2017-04-14 CVE-2017-7857 Out-of-bounds Write vulnerability in Freetype 2.7/2.7.0/2.7.1
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
network
low complexity
freetype CWE-787
critical
9.8
2012-04-25 CVE-2012-1138 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.
network
freetype mozilla CWE-119
critical
9.3
2012-04-25 CVE-2012-1135 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the NPUSHB and NPUSHW instructions in a TrueType font.
network
freetype mozilla CWE-119
critical
9.3
2012-04-25 CVE-2012-1133 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.
network
freetype mozilla CWE-119
critical
9.3
2012-04-25 CVE-2012-1129 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted SFNT string in a Type 42 font.
network
freetype mozilla CWE-119
critical
9.3
2012-04-25 CVE-2012-1128 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
network
freetype mozilla CWE-119
critical
9.3
2011-08-19 CVE-2011-2895 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.
network
freetype x freebsd netbsd openbsd CWE-119
critical
9.3