📦 Fontforge

by Fontforge

🔍 What is Fontforge?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-15277

HIGH CVSS 7.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SGI image files in FontForge. Attackers can achieve remote code execution in the context o...

CVE-2025-15278

HIGH CVSS 7.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FontForge. Attackers can exploit this by tricking users into opening malicious XBM files ...

CVE-2025-15279

HIGH CVSS 7.8 Dec 31, 2025

A heap-based buffer overflow vulnerability in FontForge's BMP file parsing allows remote attackers to execute arbitrary code when users open malicious BMP files or visit malicious web pages. This affe...

CVE-2025-15280

HIGH CVSS 8.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SFD font files or visiting malicious web pages. It affects FontForge installations where u...

CVE-2025-15271

HIGH CVSS 8.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SFD font files or visiting malicious web pages. It affects FontForge installations where u...

CVE-2025-15272

HIGH CVSS 8.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FontForge. Attackers can exploit this by tricking users into opening malicious SFD font f...

CVE-2025-15273

HIGH CVSS 8.8 Dec 31, 2025

A stack-based buffer overflow vulnerability in FontForge's PFB file parser allows remote attackers to execute arbitrary code when users open malicious PFB files or visit malicious web pages. This affe...

CVE-2025-15274

HIGH CVSS 8.8 Dec 31, 2025

A heap-based buffer overflow vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious files or visit malicious pages. This affects all F...

CVE-2025-15275

HIGH CVSS 8.8 Dec 31, 2025

A heap-based buffer overflow vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious files or visit malicious pages. This affects all F...

CVE-2025-15276

HIGH CVSS 7.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SFD font files in FontForge. Attackers can achieve remote code execution in the context of...

CVE-2025-15269

HIGH CVSS 8.8 Dec 31, 2025

A use-after-free vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious SFD files or visit malicious web pages. This affects all FontF...

CVE-2025-15270

HIGH CVSS 8.8 Dec 31, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SFD font files or visiting malicious web pages. It affects FontForge installations where u...

CVE-2025-50949

MEDIUM CVSS 6.5 Oct 23, 2025

FontForge v20230101 contains a memory leak in the DlgCreate8 component that allows attackers to cause denial of service through resource exhaustion. This affects users who process untrusted font files...