Description
FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
References (21)
... and 1 more
Scores
EPSS
0.0519
EPSS Percentile
90.0%
Details
CWE
CWE-681
Status
published
Products (9)
apple/iphone_os
< 4.2
apple/mac_os_x
< 10.6.5
apple/tvos
< 4.1.0
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.04
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
freetype/freetype
< 2.4.2
Published
Aug 19, 2010
Tracked Since
Feb 18, 2026