Known vulnerabilities in FontForge

Software: FontForge
Software CPE: cpe:2.3:a:fontforge.org:fontforge:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FontForge FontForge is affected by 21 known vulnerabilities: 19 high, 2 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121111 - Improper Validation of Array Index
CVE-2025-15270
CWE-129 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
SB2026031804
and 6 more
#VU121110 - Improper Validation of Array Index
CVE-2025-15271
CWE-129 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
#VU121109 - Heap-based Buffer Overflow
CVE-2025-15272
CWE-122 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
#VU121107 - Stack-based buffer overflow
CVE-2025-15273
CWE-121 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
#VU121102 - Heap-based Buffer Overflow
CVE-2025-15275
CWE-122 High
No
No
- 08.01.2026 SB2026010831
SB2026012758
SB2026020573
and 7 more
#VU121101 - Deserialization of Untrusted Data
CVE-2025-15276
CWE-502 High
No
No
- 08.01.2026 SB2026010831
#VU121100 - Use After Free
CVE-2025-15269
CWE-416 High
No
No
- 08.01.2026 SB2026010831
SB2026012758
SB2026020573
and 7 more
#VU121099 - Heap-based Buffer Overflow
CVE-2025-15274
CWE-122 High
No
No
- 08.01.2026 SB2026010831
#VU121098 - Use After Free
CVE-2025-15280
CWE-416 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
#VU121097 - Heap-based Buffer Overflow
CVE-2025-15277
CWE-122 High
No
No
- 08.01.2026 SB2026010831
SB2026022810
#VU121096 - Heap-based Buffer Overflow
CVE-2025-15279
CWE-122 High
No
No
- 08.01.2026 SB2026010831
SB2026012758
SB2026020573
and 7 more
#VU121095 - Integer overflow
CVE-2025-15278
CWE-190 High
No
No
- 08.01.2026 SB2026010831
#VU117705 - Missing release of memory after effective lifetime
CVE-2025-50951
CWE-401 Low
No
No
20251009 28.10.2025 SB2025102850
SB2025102852
SB2025102853
#VU117704 - Missing release of memory after effective lifetime
CVE-2025-50949
CWE-401 Low
No
No
20251009 28.10.2025 SB2025102850
SB2025102852
SB2025102853
and 10 more
#VU100255 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-25081
CWE-78 High
No
No
- 12.11.2024 SB2024111277
SB2024111280
SB2024111285
and 8 more
#VU100254 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-25082
CWE-78 High
No
No
- 12.11.2024 SB2024111277
SB2024111280
SB2024111285
and 8 more
#VU27553 - Memory corruption
CVE-2019-15785
CWE-119 High
No
No
20200314 05.05.2020 SB2019082910
SB2020043037
#VU24486 - Use After Free
CVE-2020-5395
CWE-416 High
No
No
- 22.01.2020 SB2020012218
SB2020012219
SB2020042828
and 4 more
#VU24485 - Heap-based Buffer Overflow
CVE-2020-5496
CWE-122 High
No
No
- 22.01.2020 SB2020012218
SB2020012219
SB2020043037
#VU38652 - Out-of-bounds read
CVE-2017-11573
CWE-125 High
No
No
- 24.07.2017 SB2017072416


Showing elements 1 - 20 out of 21