FontForge records
31 published records for vendor fontforge.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 64.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-122 Heap-based Buffer Overflow5
- CWE-416 Use After Free3
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-129 Improper Validation of Array Index2
The weakness classes this vendor ships most often: where to look.
CWEAll records
31 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-15785No exploit | FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.fontforge · fontforge · CWE-119 | Critical9.8 | — | 2.7% | Aug 29, 2019 |
36Monitor | CVE-2020-5395No exploit | FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.fontforge · fontforge · CWE-416 | High8.8 | — | 2.5% | Jan 3, 2020 |
36Monitor | CVE-2020-5496No exploit | FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.fontforge · fontforge · CWE-787 | High8.8 | — | 2.4% | Jan 3, 2020 |
36Monitor | CVE-2017-17521No exploit | uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable,fontforge · fontforge · CWE-74 | High8.8 | — | 1.8% | Dec 14, 2017 |
35Monitor | CVE-2020-25690No exploit | An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens.fontforge · fontforge · CWE-119 | High8.8 | — | 1.3% | Feb 23, 2021 |
35Monitor | CVE-2025-15280No exploit | FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-416 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15270No exploit | FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-129 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15271No exploit | FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-129 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15274No exploit | FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-122 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15272No exploit | FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-122 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15273No exploit | FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-121 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15275No exploit | FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-122 | High8.8 | — | 0.6% | Dec 31, 2025 |
35Monitor | CVE-2025-15269No exploit | FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-416 | High8.8 | — | 0.5% | Dec 31, 2025 |
31Monitor | CVE-2017-11571No exploit | FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a craftedfontforge · fontforge · CWE-119 | High7.8 | — | 1.4% | Jul 23, 2017 |
31Monitor | CVE-2017-11569No exploit | FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via afontforge · fontforge · CWE-125 | High7.8 | — | 1.4% | Jul 23, 2017 |
31Monitor | CVE-2017-11574No exploit | FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a craftedfontforge · fontforge · CWE-119 | High7.8 | — | 1.4% | Jul 23, 2017 |
31Monitor | CVE-2017-11568No exploit | FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution viafontforge · fontforge · CWE-125 | High7.8 | — | 1.3% | Jul 23, 2017 |
31Monitor | CVE-2017-11570No exploit | FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.fontforge · fontforge · CWE-125 | High7.8 | — | 1.3% | Jul 23, 2017 |
31Monitor | CVE-2017-11572No exploit | FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a cfontforge · fontforge · CWE-125 | High7.8 | — | 1.2% | Jul 23, 2017 |
31Monitor | CVE-2017-11575No exploit | FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, relafontforge · fontforge · CWE-125 | High7.8 | — | 1.2% | Jul 23, 2017 |
31Monitor | CVE-2017-11577No exploit | FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.fontforge · fontforge · CWE-125 | High7.8 | — | 1.2% | Jul 23, 2017 |
31Monitor | CVE-2017-11573No exploit | FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a cfontforge · fontforge · CWE-125 | High7.8 | — | 1.2% | Jul 23, 2017 |
31Monitor | CVE-2025-15276Proof of concept | FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-502 | High7.8 | — | 0.4% | Dec 31, 2025 |
31Monitor | CVE-2025-15278No exploit | FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-190 | High7.8 | — | 0.3% | Dec 31, 2025 |
31Monitor | CVE-2025-15277No exploit | FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilityfontforge · fontforge · CWE-122 | High7.8 | — | 0.3% | Dec 31, 2025 |
- CVE-2019-1578540Plan
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
CriticalCVSS 9.8No exploitEPSS 3%fontforge · fontforgeAug 29, 2019
- CVE-2020-539536Monitor
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
HighCVSS 8.8No exploitEPSS 2%fontforge · fontforgeJan 3, 2020
- CVE-2020-549636Monitor
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
HighCVSS 8.8No exploitEPSS 2%fontforge · fontforgeJan 3, 2020
- CVE-2017-1752136Monitor
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable,
HighCVSS 8.8No exploitEPSS 2%fontforge · fontforgeDec 14, 2017
- CVE-2020-2569035Monitor
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens.
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeFeb 23, 2021
- CVE-2025-1528035Monitor
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527035Monitor
FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527135Monitor
FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527435Monitor
FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527235Monitor
FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527335Monitor
FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527535Monitor
FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2025-1526935Monitor
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%fontforge · fontforgeDec 31, 2025
- CVE-2017-1157131Monitor
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1156931Monitor
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157431Monitor
FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1156831Monitor
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157031Monitor
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157231Monitor
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a c
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157531Monitor
FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, rela
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157731Monitor
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2017-1157331Monitor
FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a c
HighCVSS 7.8No exploitEPSS 1%fontforge · fontforgeJul 23, 2017
- CVE-2025-1527631Monitor
FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 0%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527831Monitor
FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%fontforge · fontforgeDec 31, 2025
- CVE-2025-1527731Monitor
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%fontforge · fontforgeDec 31, 2025