Known vulnerabilities in FontForge 20190801

Software: FontForge
Version: 20190801
Software CPE: cpe:2.3:a:fontforge.org:fontforge:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting FontForge version 20190801 FontForge 20190801 is affected by 6 vulnerabilities: 4 high, 2 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU117705 - Missing release of memory after effective lifetime
CVE-2025-50951
CWE-401 Low
No
No
20251009 28.10.2025 SB2025102850
SB2025102852
SB2025102853
#VU117704 - Missing release of memory after effective lifetime
CVE-2025-50949
CWE-401 Low
No
No
20251009 28.10.2025 SB2025102850
SB2025102852
SB2025102853
and 10 more
#VU100255 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-25081
CWE-78 High
No
No
- 12.11.2024 SB2024111277
SB2024111280
SB2024111285
and 8 more
#VU100254 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-25082
CWE-78 High
No
No
- 12.11.2024 SB2024111277
SB2024111280
SB2024111285
and 8 more
#VU24486 - Use After Free
CVE-2020-5395
CWE-416 High
No
No
- 22.01.2020 SB2020012218
SB2020012219
SB2020042828
and 4 more
#VU24485 - Heap-based Buffer Overflow
CVE-2020-5496
CWE-122 High
No
No
- 22.01.2020 SB2020012218
SB2020012219
SB2020043037