Known vulnerabilities in FontForge 20150228
Vendor:
fontforge.org
Software:
FontForge
Version:
20150228
Software CPE:
cpe:2.3:a:fontforge.org:fontforge:*:*:*:*:*:*:*:*
Website:
https://fontforge.org/en-US/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
-
20251009
20230101
20220308
2017-august-release
20201107
20100501
20190820
20190813
20200314
20190801
20190413
20190317
20170731
20170730
20161012
20161005
20161004
20161001
20160930
20160404
20160403
20150824
20150612
20150430
20150330
20150228
20141230
20141126
20141014
20141013
20140813
20120731-b
20110222
2.1.0
2.0.20140101
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117705 - Missing release of memory after effective lifetime CVE-2025-50951 |
CWE-401 | Low | 20251009 | 28.10.2025 |
SB2025102850 SB2025102852 SB2025102853 |
||
| #VU117704 - Missing release of memory after effective lifetime CVE-2025-50949 |
CWE-401 | Low | 20251009 | 28.10.2025 |
SB2025102850 SB2025102852 SB2025102853 and 10 more |
||
| #VU100255 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-25081 |
CWE-78 | High | - | 12.11.2024 |
SB2024111277 SB2024111280 SB2024111285 and 8 more |
||
| #VU100254 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-25082 |
CWE-78 | High | - | 12.11.2024 |
SB2024111277 SB2024111280 SB2024111285 and 8 more |