Vulnerabilities
31 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-15280 | FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SFD files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-28525. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-50951 +1 in the same advisory: …50949 | FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c. FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-25082 +1 in the same advisory: …25081 | Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. NVD description · AI analysis pending | 6.5 group max | 2% |
| — | ||
| CVE-2020-25690 | An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2020-5395 +1 in the same advisory: …5496 | FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2019-15785 | FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2017-17521 | uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow r uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2017-11571 | FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file. FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file. NVD description · AI analysis pending | 7.8 group max | 1% |
| — |