Перейти к содержимому
Noroxi

Записи FreeType

95 опубликованных записей вендора freetype.

Профиль для исследователя

Попали в KEV
2 · 2,1 %
С эксплойтом
2 · 2,1 %
Pre-auth RCE
47
С записью об исправлении
97,9 %
Медиана: публикация → KEV
211 дн.

Записи по годам

  1. 17
  2. 18
  3. 19
  4. 20
  5. 22
  6. 25
  7. 26

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

95 записей
  • CVE-2020-15999
    81Срочно

    Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi

    КритическаяCVSS 9,6KEVГотовый эксплойтEPSS 44 %

    google · chrome2 нояб. 2020 г.

  • CVE-2025-27363
    70На этой неделе

    An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 28 %

    freetype · freetype11 мар. 2025 г.

  • CVE-2012-1126
    42В плане

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 10,0Эксплойта нетEPSS 6 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2011-2895
    40В плане

    The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress

    КритическаяCVSS 9,3Эксплойта нетEPSS 8 %

    x · libxfont19 авг. 2011 г.

  • CVE-2017-8105
    40В плане

    FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings f

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    freetype · freetype24 апр. 2017 г.

  • CVE-2017-7864
    40В плане

    FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in true

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    freetype · freetype14 апр. 2017 г.

  • CVE-2016-10328
    40В плане

    FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    freetype · freetype14 апр. 2017 г.

  • CVE-2017-8287
    40В плане

    FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour funct

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    freetype · freetype26 апр. 2017 г.

  • CVE-2017-7857
    40В плане

    FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in true

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    freetype · freetype14 апр. 2017 г.

  • CVE-2017-7858
    40В плане

    FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face f

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    freetype · freetype14 апр. 2017 г.

  • CVE-2014-9746
    40В плане

    The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix func

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    freetype · freetype7 июн. 2016 г.

  • CVE-2015-9290
    40В плане

    In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    freetype · freetype30 июл. 2019 г.

  • CVE-2022-27404
    40В плане

    FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    freetype · freetype22 апр. 2022 г.

  • CVE-2010-3311
    39Наблюдать

    Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial

    КритическаяCVSS 9,3Эксплойта нетEPSS 7 %

    freetype · freetype7 янв. 2011 г.

  • CVE-2011-0226
    39Наблюдать

    Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.

    КритическаяCVSS 9,3Эксплойта нетEPSS 7 %

    freetype · freetype19 июл. 2011 г.

  • CVE-2012-1144
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1138
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1135
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1133
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1128
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1134
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1140
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1130
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1139
    38Наблюдать

    Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to c

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    freetype · freetype25 апр. 2012 г.

  • CVE-2012-1142
    38Наблюдать

    FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    freetype · freetype25 апр. 2012 г.