Search CVE reports


Toggle filters

11 – 20 of 32 results


CVE-2025-15270

Medium priority
Vulnerable

FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is...

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-15269

Medium priority
Vulnerable

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit...

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-50951

Low priority
Vulnerable

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2025-50949

Low priority
Vulnerable

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-25082

Medium priority
Fixed

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-25081

Medium priority
Fixed

Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected Fixed Fixed Fixed
Show less packages

CVE-2020-25690

Medium priority
Needs evaluation

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the...

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-5496

Medium priority
Needs evaluation

FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-5395

Medium priority
Needs evaluation

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2019-15785

Medium priority
Not affected

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

1 affected package

fontforge

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fontforge Not affected
Show less packages