Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

fontforge — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in fontforge, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities and weaknesses associated with the fontforge vector graphics editor. It serves as a centralized resource for tracking security issues related to this open-source software application. The content aggregates data from various public sources, including Common Vulnerabilities and Exposures (CVE) entries, vendor advisories, and security research reports. The vulnerabilities collected here primarily involve issues such as buffer overflows, integer overflows, use-after-free errors, and improper input validation within font parsing routines. These flaws can potentially lead to arbitrary code execution, denial of service, or information disclosure when processing maliciously crafted font files. The coverage spans multiple years, capturing historical vulnerabilities affecting older versions as well as more recent discoveries in current releases. This broad time range allows users to understand the long-term security posture of the software and how remediation efforts have evolved over time. Visitors can use this page to track the fontforge vendor's security advisories and patch release history. Users can also gain a deeper understanding of specific weakness classes prevalent in font processing libraries. Additionally, developers and security researchers can look up the complete vulnerability history of the product to assess risk levels for specific versions. By reviewing these aggregated details, stakeholders can better prioritize updates, configure their environments securely, and mitigate potential threats posed by unpatched software components.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2025-15279 FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 - 2025-12-31
CVE-2025-15278 FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability CWE-190 7.8 - 2025-12-31
CVE-2025-15277 FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 - 2025-12-31
CVE-2025-15276 FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability CWE-502 7.8 - 2025-12-31
CVE-2025-15280 FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability CWE-416 7.8 - 2025-12-31
CVE-2025-15275 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 - 2025-12-31
CVE-2025-15274 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 - 2025-12-31
CVE-2025-15273 FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 7.8 - 2025-12-31
CVE-2025-15272 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 7.8 - 2025-12-31
CVE-2025-15271 FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability CWE-129 7.8 - 2025-12-31
CVE-2025-15270 FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability CWE-129 7.8 - 2025-12-31
CVE-2025-15269 FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability CWE-416 7.8 - 2025-12-31
CVE-2020-25690 Red Hat Enterprise Linux 8 缓冲区错误漏洞 CWE-119 8.8 - 2021-02-23

All 13 known CVE vulnerabilities affecting fontforge with full Chinese analysis, references, and POCs where available.