Записи FreeType
95 опубликованных записей вендора freetype.
Профиль для исследователя
- Попали в KEV
- 2 · 2,1 %
- С эксплойтом
- 2 · 2,1 %
- Pre-auth RCE
- 47
- С записью об исправлении
- 97,9 %
- Медиана: публикация → KEV
- 211 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer36
- CWE-125 Out-of-bounds Read11
- CWE-787 Out-of-bounds Write11
- CWE-189 Numeric Errors11
- CWE-20 Improper Input Validation4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
95 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
81Срочно | CVE-2020-15999Готовый эксплойт | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vigoogle · chrome · CWE-787 | Критическая9,6 | KEV | 44,3 % | 2 нояб. 2020 г. |
70На этой неделе | CVE-2025-27363Готовый эксплойт | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parsefreetype · freetype · CWE-787 | Высокая8,1 | KEV | 27,8 % | 11 мар. 2025 г. |
42В плане | CVE-2012-1126Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая10,0 | — | 5,6 % | 25 апр. 2012 г. |
40В плане | CVE-2011-2895Эксплойта нет | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compressx · libxfont · CWE-119 | Критическая9,3 | — | 8,4 % | 19 авг. 2011 г. |
40В плане | CVE-2017-8105Эксплойта нет | FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings ffreetype · freetype · CWE-787 | Критическая9,8 | — | 4,4 % | 24 апр. 2017 г. |
40В плане | CVE-2017-7864Эксплойта нет | FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truefreetype · freetype · CWE-787 | Критическая9,8 | — | 3,8 % | 14 апр. 2017 г. |
40В плане | CVE-2016-10328Эксплойта нет | FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cfffreetype · freetype · CWE-787 | Критическая9,8 | — | 3,7 % | 14 апр. 2017 г. |
40В плане | CVE-2017-8287Эксплойта нет | FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour functfreetype · freetype · CWE-119 | Критическая9,8 | — | 3,6 % | 26 апр. 2017 г. |
40В плане | CVE-2017-7857Эксплойта нет | FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truefreetype · freetype · CWE-787 | Критическая9,8 | — | 3,6 % | 14 апр. 2017 г. |
40В плане | CVE-2017-7858Эксплойта нет | FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face ffreetype · freetype · CWE-787 | Критическая9,8 | — | 3,4 % | 14 апр. 2017 г. |
40В плане | CVE-2014-9746Эксплойта нет | The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix funcfreetype · freetype · CWE-20 | Критическая9,8 | — | 3,3 % | 7 июн. 2016 г. |
40В плане | CVE-2015-9290Эксплойта нет | In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new freetype · freetype · CWE-125 | Критическая9,8 | — | 2,7 % | 30 июл. 2019 г. |
40В плане | CVE-2022-27404Эксплойта нет | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.freetype · freetype · CWE-787 | Критическая9,8 | — | 2,7 % | 22 апр. 2022 г. |
39Наблюдать | CVE-2010-3311Эксплойта нет | Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial freetype · freetype · CWE-189 | Критическая9,3 | — | 6,7 % | 7 янв. 2011 г. |
39Наблюдать | CVE-2011-0226Эксплойта нет | Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.freetype · freetype · CWE-189 | Критическая9,3 | — | 6,6 % | 19 июл. 2011 г. |
38Наблюдать | CVE-2012-1144Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,9 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1138Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,7 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1135Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,7 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1133Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,7 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1128Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,6 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1134Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 4,6 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1140Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 3,8 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1130Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 3,8 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1139Эксплойта нет | Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cfreetype · freetype · CWE-119 | Критическая9,3 | — | 3,8 % | 25 апр. 2012 г. |
38Наблюдать | CVE-2012-1142Эксплойта нет | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Критическая9,3 | — | 3,8 % | 25 апр. 2012 г. |
- CVE-2020-1599981Срочно
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi
КритическаяCVSS 9,6KEVГотовый эксплойтEPSS 44 %google · chrome2 нояб. 2020 г.
- CVE-2025-2736370На этой неделе
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 28 %freetype · freetype11 мар. 2025 г.
- CVE-2012-112642В плане
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %freetype · freetype25 апр. 2012 г.
- CVE-2011-289540В плане
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %x · libxfont19 авг. 2011 г.
- CVE-2017-810540В плане
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings f
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freetype · freetype24 апр. 2017 г.
- CVE-2017-786440В плане
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in true
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freetype · freetype14 апр. 2017 г.
- CVE-2016-1032840В плане
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freetype · freetype14 апр. 2017 г.
- CVE-2017-828740В плане
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour funct
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freetype · freetype26 апр. 2017 г.
- CVE-2017-785740В плане
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in true
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freetype · freetype14 апр. 2017 г.
- CVE-2017-785840В плане
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face f
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %freetype · freetype14 апр. 2017 г.
- CVE-2014-974640В плане
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix func
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %freetype · freetype7 июн. 2016 г.
- CVE-2015-929040В плане
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %freetype · freetype30 июл. 2019 г.
- CVE-2022-2740440В плане
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %freetype · freetype22 апр. 2022 г.
- CVE-2010-331139Наблюдать
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %freetype · freetype7 янв. 2011 г.
- CVE-2011-022639Наблюдать
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %freetype · freetype19 июл. 2011 г.
- CVE-2012-114438Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113838Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113538Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113338Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-112838Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113438Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %freetype · freetype25 апр. 2012 г.
- CVE-2012-114038Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113038Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %freetype · freetype25 апр. 2012 г.
- CVE-2012-113938Наблюдать
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to c
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %freetype · freetype25 апр. 2012 г.
- CVE-2012-114238Наблюдать
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %freetype · freetype25 апр. 2012 г.