FreeType records
95 published records for vendor freetype.
Researcher profile
- Entered KEV
- 2 · 2.1%
- Weaponized
- 2 · 2.1%
- Pre-auth RCE
- 47
- With a fix record
- 97.9%
- Median publish → KEV
- 211 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer36
- CWE-125 Out-of-bounds Read11
- CWE-787 Out-of-bounds Write11
- CWE-189 Numeric Errors11
- CWE-20 Improper Input Validation4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
95 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
81Now | CVE-2020-15999Weaponized | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vigoogle · chrome · CWE-787 | Critical9.6 | KEV | 44.3% | Nov 2, 2020 |
70This week | CVE-2025-27363Weaponized | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parsefreetype · freetype · CWE-787 | High8.1 | KEV | 27.8% | Mar 11, 2025 |
42Plan | CVE-2012-1126No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical10.0 | — | 5.6% | Apr 25, 2012 |
40Plan | CVE-2011-2895No exploit | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compressx · libxfont · CWE-119 | Critical9.3 | — | 8.4% | Aug 19, 2011 |
40Plan | CVE-2017-8105No exploit | FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings ffreetype · freetype · CWE-787 | Critical9.8 | — | 4.4% | Apr 24, 2017 |
40Plan | CVE-2017-7864No exploit | FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truefreetype · freetype · CWE-787 | Critical9.8 | — | 3.8% | Apr 14, 2017 |
40Plan | CVE-2016-10328No exploit | FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cfffreetype · freetype · CWE-787 | Critical9.8 | — | 3.7% | Apr 14, 2017 |
40Plan | CVE-2017-8287No exploit | FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour functfreetype · freetype · CWE-119 | Critical9.8 | — | 3.6% | Apr 26, 2017 |
40Plan | CVE-2017-7857No exploit | FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truefreetype · freetype · CWE-787 | Critical9.8 | — | 3.6% | Apr 14, 2017 |
40Plan | CVE-2017-7858No exploit | FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face ffreetype · freetype · CWE-787 | Critical9.8 | — | 3.4% | Apr 14, 2017 |
40Plan | CVE-2014-9746No exploit | The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix funcfreetype · freetype · CWE-20 | Critical9.8 | — | 3.3% | Jun 7, 2016 |
40Plan | CVE-2015-9290No exploit | In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new freetype · freetype · CWE-125 | Critical9.8 | — | 2.7% | Jul 30, 2019 |
40Plan | CVE-2022-27404No exploit | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.freetype · freetype · CWE-787 | Critical9.8 | — | 2.7% | Apr 22, 2022 |
39Monitor | CVE-2010-3311No exploit | Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial freetype · freetype · CWE-189 | Critical9.3 | — | 6.7% | Jan 7, 2011 |
39Monitor | CVE-2011-0226No exploit | Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.freetype · freetype · CWE-189 | Critical9.3 | — | 6.6% | Jul 19, 2011 |
38Monitor | CVE-2012-1144No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.9% | Apr 25, 2012 |
38Monitor | CVE-2012-1138No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.7% | Apr 25, 2012 |
38Monitor | CVE-2012-1135No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.7% | Apr 25, 2012 |
38Monitor | CVE-2012-1133No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.7% | Apr 25, 2012 |
38Monitor | CVE-2012-1128No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.6% | Apr 25, 2012 |
38Monitor | CVE-2012-1134No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 4.6% | Apr 25, 2012 |
38Monitor | CVE-2012-1140No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 3.8% | Apr 25, 2012 |
38Monitor | CVE-2012-1130No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 3.8% | Apr 25, 2012 |
38Monitor | CVE-2012-1139No exploit | Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cfreetype · freetype · CWE-119 | Critical9.3 | — | 3.8% | Apr 25, 2012 |
38Monitor | CVE-2012-1142No exploit | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Critical9.3 | — | 3.8% | Apr 25, 2012 |
- CVE-2020-1599981Now
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi
CriticalCVSS 9.6KEVWeaponizedEPSS 44%google · chromeNov 2, 2020
- CVE-2025-2736370This week
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse
HighCVSS 8.1KEVWeaponizedEPSS 28%freetype · freetypeMar 11, 2025
- CVE-2012-112642Plan
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 6%freetype · freetypeApr 25, 2012
- CVE-2011-289540Plan
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress
CriticalCVSS 9.3No exploitEPSS 8%x · libxfontAug 19, 2011
- CVE-2017-810540Plan
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings f
CriticalCVSS 9.8No exploitEPSS 4%freetype · freetypeApr 24, 2017
- CVE-2017-786440Plan
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in true
CriticalCVSS 9.8No exploitEPSS 4%freetype · freetypeApr 14, 2017
- CVE-2016-1032840Plan
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff
CriticalCVSS 9.8No exploitEPSS 4%freetype · freetypeApr 14, 2017
- CVE-2017-828740Plan
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour funct
CriticalCVSS 9.8No exploitEPSS 4%freetype · freetypeApr 26, 2017
- CVE-2017-785740Plan
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in true
CriticalCVSS 9.8No exploitEPSS 4%freetype · freetypeApr 14, 2017
- CVE-2017-785840Plan
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face f
CriticalCVSS 9.8No exploitEPSS 3%freetype · freetypeApr 14, 2017
- CVE-2014-974640Plan
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix func
CriticalCVSS 9.8No exploitEPSS 3%freetype · freetypeJun 7, 2016
- CVE-2015-929040Plan
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new
CriticalCVSS 9.8No exploitEPSS 3%freetype · freetypeJul 30, 2019
- CVE-2022-2740440Plan
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
CriticalCVSS 9.8No exploitEPSS 3%freetype · freetypeApr 22, 2022
- CVE-2010-331139Monitor
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial
CriticalCVSS 9.3No exploitEPSS 7%freetype · freetypeJan 7, 2011
- CVE-2011-022639Monitor
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.
CriticalCVSS 9.3No exploitEPSS 7%freetype · freetypeJul 19, 2011
- CVE-2012-114438Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-113838Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-113538Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-113338Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-112838Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-113438Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 5%freetype · freetypeApr 25, 2012
- CVE-2012-114038Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 4%freetype · freetypeApr 25, 2012
- CVE-2012-113038Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 4%freetype · freetypeApr 25, 2012
- CVE-2012-113938Monitor
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to c
CriticalCVSS 9.3No exploitEPSS 4%freetype · freetypeApr 25, 2012
- CVE-2012-114238Monitor
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
CriticalCVSS 9.3No exploitEPSS 4%freetype · freetypeApr 25, 2012