Skip to content
Noroxi

FreeType records

95 published records for vendor freetype.

Researcher profile

Entered KEV
2 · 2.1%
Weaponized
2 · 2.1%
Pre-auth RCE
47
With a fix record
97.9%
Median publish → KEV
211 days

All records

95 records
  • Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi

    CriticalCVSS 9.6KEVWeaponizedEPSS 44%

    google · chromeNov 2, 2020

  • CVE-2025-27363
    70This week

    An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse

    HighCVSS 8.1KEVWeaponizedEPSS 28%

    freetype · freetypeMar 11, 2025

  • FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 10.0No exploitEPSS 6%

    freetype · freetypeApr 25, 2012

  • The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress

    CriticalCVSS 9.3No exploitEPSS 8%

    x · libxfontAug 19, 2011

  • FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings f

    CriticalCVSS 9.8No exploitEPSS 4%

    freetype · freetypeApr 24, 2017

  • FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in true

    CriticalCVSS 9.8No exploitEPSS 4%

    freetype · freetypeApr 14, 2017

  • FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff

    CriticalCVSS 9.8No exploitEPSS 4%

    freetype · freetypeApr 14, 2017

  • FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour funct

    CriticalCVSS 9.8No exploitEPSS 4%

    freetype · freetypeApr 26, 2017

  • FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in true

    CriticalCVSS 9.8No exploitEPSS 4%

    freetype · freetypeApr 14, 2017

  • FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face f

    CriticalCVSS 9.8No exploitEPSS 3%

    freetype · freetypeApr 14, 2017

  • The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix func

    CriticalCVSS 9.8No exploitEPSS 3%

    freetype · freetypeJun 7, 2016

  • In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new

    CriticalCVSS 9.8No exploitEPSS 3%

    freetype · freetypeJul 30, 2019

  • FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

    CriticalCVSS 9.8No exploitEPSS 3%

    freetype · freetypeApr 22, 2022

  • CVE-2010-3311
    39Monitor

    Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial

    CriticalCVSS 9.3No exploitEPSS 7%

    freetype · freetypeJan 7, 2011

  • CVE-2011-0226
    39Monitor

    Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.

    CriticalCVSS 9.3No exploitEPSS 7%

    freetype · freetypeJul 19, 2011

  • CVE-2012-1144
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1138
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1135
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1133
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1128
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1134
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 5%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1140
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 4%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1130
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 4%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1139
    38Monitor

    Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to c

    CriticalCVSS 9.3No exploitEPSS 4%

    freetype · freetypeApr 25, 2012

  • CVE-2012-1142
    38Monitor

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    CriticalCVSS 9.3No exploitEPSS 4%

    freetype · freetypeApr 25, 2012