Skip to content
Noroxi

FontForge records

31 published records for vendor fontforge.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
10
With a fix record
64.5%
Median publish → KEV
No record has entered KEV

All records

31 records
  • FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

    CriticalCVSS 9.8No exploitEPSS 3%

    fontforge · fontforgeAug 29, 2019

  • CVE-2020-5395
    36Monitor

    FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

    HighCVSS 8.8No exploitEPSS 2%

    fontforge · fontforgeJan 3, 2020

  • CVE-2020-5496
    36Monitor

    FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

    HighCVSS 8.8No exploitEPSS 2%

    fontforge · fontforgeJan 3, 2020

  • uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable,

    HighCVSS 8.8No exploitEPSS 2%

    fontforge · fontforgeDec 14, 2017

  • An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens.

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeFeb 23, 2021

  • FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    fontforge · fontforgeDec 31, 2025

  • FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a c

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, rela

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a c

    HighCVSS 7.8No exploitEPSS 1%

    fontforge · fontforgeJul 23, 2017

  • FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

    HighCVSS 7.8Proof of conceptEPSS 0%

    fontforge · fontforgeDec 31, 2025

  • FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    fontforge · fontforgeDec 31, 2025

  • FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    fontforge · fontforgeDec 31, 2025