CVE-2024-25082
MEDIUMFontForge <20230101 - Command Injection
Title source: llmDescription
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Exploits (4)
nomisec
WORKING POC
by AliElKhatteb · poc
https://github.com/AliElKhatteb/CVE-2024-25082_CVE-2024-25081
References (6)
Scores
CVSS v3
6.5
EPSS
0.0137
EPSS Percentile
80.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-77
Status
published
Products (3)
debian/debian_linux
10.0
fedoraproject/fedora
40
fontforge/fontforge
< 20230101
Published
Feb 26, 2024
Tracked Since
Feb 18, 2026