Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23865

Опубликовано: 02 мар. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
Версия от 2.13.2 (включая) до 2.13.3 (включая)
cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*
Версия от 2.14.0 (включая) до 2.14.1 (включая)

EPSS

Процентиль: 4%
0.00141
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
redhat
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
msrc
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

CVSS3: 5.3
debian
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function o ...

CVSS3: 5.3
github
5 месяцев назад

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

EPSS

Процентиль: 4%
0.00141
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125