Fontforge
This hub aggregates every CVE we track for Fontforge, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
32
CVEs tracked
1
Critical
25
High
0
In CISA KEV
Severity distribution
HIGH25MEDIUM6CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
2
0
12
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Fontforge.
- CVE-2025-15279FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability7.8
- CVE-2025-15278FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability7.8
- CVE-2025-15277FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability7.8
- CVE-2025-15276FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability7.8
- CVE-2025-15280FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability8.8
- CVE-2025-15275FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2025-15274FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2025-15273FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2025-15272FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2025-15271FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability8.8
- CVE-2025-15270FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability8.8
- CVE-2025-15269FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability8.8
- CVE-2025-50949FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.6.5
- CVE-2025-50951FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.6.5
- CVE-2024-25081Splinefont in FontForge through 20230101 allows command injection via crafted filenames.4.2
Product normalization is registry-driven with AI assist and human review. How it works