ZeroHour

Vulnerabilities

31 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-15280
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability.

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-28525.

NVD description · AI analysis pending
8.8
group max
<1%
  • fontforge fontforge
CVE-2025-50951
+1 in the same advisory: …50949
FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

NVD description · AI analysis pending
6.5<1%
  • fontforge fontforge
CVE-2024-25082
+1 in the same advisory: …25081
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

NVD description · AI analysis pending
6.5
group max
2%
  • fontforge fontforge
  • fontforge debian linux
  • fontforge fedora
CVE-2020-25690
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens.

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

NVD description · AI analysis pending
8.81%
  • fontforge fontforge
CVE-2020-5395
+1 in the same advisory: …5496
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

NVD description · AI analysis pending
8.82% PoC
  • fontforge fontforge
  • fontforge fedora
  • fontforge leap
CVE-2019-15785
FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

NVD description · AI analysis pending
9.83% PoC
  • fontforge fontforge
CVE-2017-17521
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow r

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

NVD description · AI analysis pending
8.82%
  • fontforge fontforge
CVE-2017-11571
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

NVD description · AI analysis pending
7.8
group max
1%
  • fontforge fontforge