Debian Freetype vulnerabilities
94 known vulnerabilities affecting debian/freetype.
Total CVEs
94
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL16HIGH20MEDIUM37LOW21
Vulnerabilities
Page 1 of 5
CVE-2020-15999P1CRITICALCVSS 9.6KEVPoCfixed in freetype 2.10.2+dfsg-4 (bookworm)2020
CVE-2020-15999 [CRITICAL] CVE-2020-15999: freetype - Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed...
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 2.10.2+dfsg-4)
bullseye: resolved (fixed in 2.10.2+dfsg-4)
forky: resolved (fixed in 2.10.2+dfsg-4)
sid: resolved (fixed in 2.10.2+dfsg-4)
trixie: resolved (f
debian
CVE-2025-27363P1HIGHCVSS 8.1KEVPoCfixed in freetype 2.12.1+dfsg-5+deb12u4 (bookworm)2025
CVE-2025-27363 [HIGH] CVE-2025-27363: freetype - An out of bounds write exists in FreeType versions 2.13.0 and below (newer versi...
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a h
debian
CVE-2010-1797P2CRITICALCVSS 9.3ExploitedPoCfixed in freetype 2.4.2-1 (bookworm)2010
CVE-2010-1797 [CRITICAL] CVE-2010-1797: freetype - Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings funct...
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via c
debian
CVE-2011-0226P2CRITICALCVSS 9.3Exploitedfixed in freetype 2.4.6-1 (bookworm)2011
CVE-2011-0226 [CRITICAL] CVE-2011-0226: freetype - Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used i...
Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 20
debian
CVE-2017-8105P3CRITICALCVSS 9.8fixed in freetype 2.6.3-3.2 (bookworm)2017
CVE-2017-8105 [CRITICAL] CVE-2017-8105: freetype - FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based b...
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
Scope: local
bookworm: resolved (fixed in 2.6.3-3.2)
bullseye: resolved (fixed in 2.6.3-3.2)
forky: resolved (fixed in 2.6.3-3.2)
sid: resolved (fixed in 2.6.3-3.2)
trixie: resolved (fixed in 2.6.
debian
CVE-2017-8287P3CRITICALCVSS 9.8fixed in freetype 2.6.3-3.2 (bookworm)2017
CVE-2017-8287 [CRITICAL] CVE-2017-8287: freetype - FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based b...
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
Scope: local
bookworm: resolved (fixed in 2.6.3-3.2)
bullseye: resolved (fixed in 2.6.3-3.2)
forky: resolved (fixed in 2.6.3-3.2)
sid: resolved (fixed in 2.6.3-3.2)
trixie: resolved (fixed in 2.6.3-3.2)
debian
CVE-2022-27404P3CRITICALCVSS 9.8fixed in freetype 2.11.1+dfsg-2 (bookworm)2022
CVE-2022-27404 [CRITICAL] CVE-2022-27404: freetype - FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to conta...
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Scope: local
bookworm: resolved (fixed in 2.11.1+dfsg-2)
bullseye: resolved (fixed in 2.10.4+dfsg-1+deb11u1)
forky: resolved (fixed in 2.11.1+dfsg-2)
sid: resolved (fixed in 2.11.1+dfsg-2)
trixie: resolved (fixed in 2.11.1+d
debian
CVE-2009-0946P3MEDIUMCVSS 7.5fixed in freetype 2.3.9-4.1 (bookworm)2009
CVE-2009-0946 [HIGH] CVE-2009-0946: freetype - Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers ...
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
Scope: local
bookworm: resolved (fixed in 2.3.9-4.1)
bullseye: resolved (fixed in 2.3.9-4.1)
forky: resolved (fixed in 2.3.9-4.1)
sid: resolv
debian
CVE-2014-9659P3HIGHCVSS 7.5fixed in freetype 2.5.2-3 (bookworm)2014
CVE-2014-9659 [HIGH] CVE-2014-9659: freetype - cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 procee...
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.
S
debian
CVE-2006-2661P4MEDIUMCVSS 5.0PoCfixed in freetype 2.2.1-1 (bookworm)2006
CVE-2006-2661 [MEDIUM] CVE-2006-2661: freetype - ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of ser...
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
Scope: local
bookworm: resolved (fixed in 2.2.1-1)
bullseye: resolved (fixed in 2.2.1-1)
forky: resolved (fixed in 2.2.1-1)
sid: resolved (fixed in 2.2.1-1)
trixie: resolved (fixed in 2.2.1-1)
debian
CVE-2011-3439P3CRITICALCVSS 9.3fixed in freetype 2.4.8-1 (bookworm)2011
CVE-2011-3439 [CRITICAL] CVE-2011-3439: freetype - FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to ex...
FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.
Scope: local
bookworm: resolved (fixed in 2.4.8-1)
bullseye: resolved (fixed in 2.4.8-1)
forky: resolved (fixed in 2.4.8-1)
sid: resolved (fixed in 2.4.8-1)
trixie: resolved (fixed
debian
CVE-2012-1133P3CRITICALCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1133 [CRITICAL] CVE-2012-1133: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9
debian
CVE-2012-1134P3CRITICALCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1134 [CRITICAL] CVE-2012-1134: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted private-dictionary data in a Type 1 font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in
debian
CVE-2012-1126P3LOWCVSS 10.0fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1126 [CRITICAL] CVE-2012-1126: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
fork
debian
CVE-2006-0747P4MEDIUMCVSS 5.0PoCfixed in freetype 2.2.1-1 (bookworm)2006
CVE-2006-0747 [MEDIUM] CVE-2006-0747: freetype - Integer underflow in Freetype before 2.2 allows remote attackers to cause a deni...
Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.
Scope: local
bookworm: resolved (fixed in 2.2.1-1)
bullseye: resolved (fixed in 2.2.1-1)
forky: resolved (fixed
debian
CVE-2012-1144P3CRITICALCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1144 [CRITICAL] CVE-2012-1144: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
forky: resolved
debian
CVE-2014-9746P3CRITICALCVSS 9.8fixed in freetype 2.6-1 (bookworm)2014
CVE-2014-9746 [CRITICAL] CVE-2014-9746: freetype - The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matr...
The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access a
debian
CVE-2012-1142P3CRITICALCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1142 [CRITICAL] CVE-2012-1142: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
fo
debian
CVE-2012-1136P3CRITICALCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1136 [CRITICAL] CVE-2012-1136: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font that lacks an ENCODING field.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bulls
debian
CVE-2012-1132P3LOWCVSS 9.3fixed in freetype 2.4.9-1 (bookworm)2012
CVE-2012-1132 [CRITICAL] CVE-2012-1132: freetype - FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other...
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted dictionary data in a Type 1 font.
Scope: local
bookworm: resolved (fixed in 2.4.9-1)
bullseye: resolved (fixed in 2.4.9-1)
debian
1 / 5Next →