FreeType kayıtları
freetype üreticisine ait 95 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %2,1
- Silahlaştırılmış
- 2 · %2,1
- Pre-auth RCE
- 47
- Düzeltme kaydı olan
- %97,9
- Yayından KEV’e ortanca
- 211 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer36
- CWE-125 Out-of-bounds Read11
- CWE-787 Out-of-bounds Write11
- CWE-189 Numeric Errors11
- CWE-20 Improper Input Validation4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
95 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
81Hemen | CVE-2020-15999Silahlaştırılmış | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vigoogle · chrome · CWE-787 | Kritik9,6 | KEV | %44,3 | 2 Kas 2020 |
70Bu hafta | CVE-2025-27363Silahlaştırılmış | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parsefreetype · freetype · CWE-787 | Yüksek8,1 | KEV | %27,8 | 11 Mar 2025 |
42Planlayın | CVE-2012-1126İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik10,0 | — | %5,6 | 25 Nis 2012 |
40Planlayın | CVE-2011-2895İstismar yok | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compressx · libxfont · CWE-119 | Kritik9,3 | — | %8,4 | 19 Ağu 2011 |
40Planlayın | CVE-2017-8105İstismar yok | FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings ffreetype · freetype · CWE-787 | Kritik9,8 | — | %4,4 | 24 Nis 2017 |
40Planlayın | CVE-2017-7864İstismar yok | FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truefreetype · freetype · CWE-787 | Kritik9,8 | — | %3,8 | 14 Nis 2017 |
40Planlayın | CVE-2016-10328İstismar yok | FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cfffreetype · freetype · CWE-787 | Kritik9,8 | — | %3,7 | 14 Nis 2017 |
40Planlayın | CVE-2017-8287İstismar yok | FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour functfreetype · freetype · CWE-119 | Kritik9,8 | — | %3,6 | 26 Nis 2017 |
40Planlayın | CVE-2017-7857İstismar yok | FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truefreetype · freetype · CWE-787 | Kritik9,8 | — | %3,6 | 14 Nis 2017 |
40Planlayın | CVE-2017-7858İstismar yok | FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face ffreetype · freetype · CWE-787 | Kritik9,8 | — | %3,4 | 14 Nis 2017 |
40Planlayın | CVE-2014-9746İstismar yok | The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix funcfreetype · freetype · CWE-20 | Kritik9,8 | — | %3,3 | 7 Haz 2016 |
40Planlayın | CVE-2015-9290İstismar yok | In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new freetype · freetype · CWE-125 | Kritik9,8 | — | %2,7 | 30 Tem 2019 |
40Planlayın | CVE-2022-27404İstismar yok | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.freetype · freetype · CWE-787 | Kritik9,8 | — | %2,7 | 22 Nis 2022 |
39İzleyin | CVE-2010-3311İstismar yok | Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial freetype · freetype · CWE-189 | Kritik9,3 | — | %6,7 | 7 Oca 2011 |
39İzleyin | CVE-2011-0226İstismar yok | Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.freetype · freetype · CWE-189 | Kritik9,3 | — | %6,6 | 19 Tem 2011 |
38İzleyin | CVE-2012-1144İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,9 | 25 Nis 2012 |
38İzleyin | CVE-2012-1138İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,7 | 25 Nis 2012 |
38İzleyin | CVE-2012-1135İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,7 | 25 Nis 2012 |
38İzleyin | CVE-2012-1133İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,7 | 25 Nis 2012 |
38İzleyin | CVE-2012-1128İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,6 | 25 Nis 2012 |
38İzleyin | CVE-2012-1134İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %4,6 | 25 Nis 2012 |
38İzleyin | CVE-2012-1140İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %3,8 | 25 Nis 2012 |
38İzleyin | CVE-2012-1130İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %3,8 | 25 Nis 2012 |
38İzleyin | CVE-2012-1139İstismar yok | Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cfreetype · freetype · CWE-119 | Kritik9,3 | — | %3,8 | 25 Nis 2012 |
38İzleyin | CVE-2012-1142İstismar yok | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of servfreetype · freetype · CWE-119 | Kritik9,3 | — | %3,8 | 25 Nis 2012 |
- CVE-2020-1599981Hemen
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption vi
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %44google · chrome2 Kas 2020
- CVE-2025-2736370Bu hafta
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %28freetype · freetype11 Mar 2025
- CVE-2012-112642Planlayın
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %6freetype · freetype25 Nis 2012
- CVE-2011-289540Planlayın
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress
KritikCVSS 9,3İstismar yokEPSS %8x · libxfont19 Ağu 2011
- CVE-2017-810540Planlayın
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings f
KritikCVSS 9,8İstismar yokEPSS %4freetype · freetype24 Nis 2017
- CVE-2017-786440Planlayın
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in true
KritikCVSS 9,8İstismar yokEPSS %4freetype · freetype14 Nis 2017
- CVE-2016-1032840Planlayın
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff
KritikCVSS 9,8İstismar yokEPSS %4freetype · freetype14 Nis 2017
- CVE-2017-828740Planlayın
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour funct
KritikCVSS 9,8İstismar yokEPSS %4freetype · freetype26 Nis 2017
- CVE-2017-785740Planlayın
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in true
KritikCVSS 9,8İstismar yokEPSS %4freetype · freetype14 Nis 2017
- CVE-2017-785840Planlayın
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face f
KritikCVSS 9,8İstismar yokEPSS %3freetype · freetype14 Nis 2017
- CVE-2014-974640Planlayın
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix func
KritikCVSS 9,8İstismar yokEPSS %3freetype · freetype7 Haz 2016
- CVE-2015-929040Planlayın
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new
KritikCVSS 9,8İstismar yokEPSS %3freetype · freetype30 Tem 2019
- CVE-2022-2740440Planlayın
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
KritikCVSS 9,8İstismar yokEPSS %3freetype · freetype22 Nis 2022
- CVE-2010-331139İzleyin
Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial
KritikCVSS 9,3İstismar yokEPSS %7freetype · freetype7 Oca 2011
- CVE-2011-022639İzleyin
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.
KritikCVSS 9,3İstismar yokEPSS %7freetype · freetype19 Tem 2011
- CVE-2012-114438İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-113838İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-113538İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-113338İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-112838İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-113438İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %5freetype · freetype25 Nis 2012
- CVE-2012-114038İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %4freetype · freetype25 Nis 2012
- CVE-2012-113038İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %4freetype · freetype25 Nis 2012
- CVE-2012-113938İzleyin
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to c
KritikCVSS 9,3İstismar yokEPSS %4freetype · freetype25 Nis 2012
- CVE-2012-114238İzleyin
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of serv
KritikCVSS 9,3İstismar yokEPSS %4freetype · freetype25 Nis 2012