CVE-2024-25081
MEDIUMFontForge <20230101 - Command Injection
Title source: llmDescription
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
Exploits (1)
References (6)
Scores
CVSS v3
4.2
EPSS
0.0004
EPSS Percentile
11.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-77
Status
published
Products (3)
debian/debian_linux
10.0
fedoraproject/fedora
40
fontforge/fontforge
< 20230101
Published
Feb 26, 2024
Tracked Since
Feb 18, 2026