Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

fstec логотип

BDU:2025-02719

больше 3 лет назад

Уязвимость библиотеки для растеризации шрифтов FreeType, связанная с чтением за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
EPSS: Средний
redos логотип

ROS-20250722-03

около 1 года назад

Уязвимость FreeType

CVSS3: 8.1
EPSS: Средний
ubuntu логотип

CVE-2025-27363

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2025-27363

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2025-27363

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
EPSS: Средний
msrc логотип

CVE-2025-27363

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
EPSS: Средний
debian логотип

CVE-2025-27363

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below (n ...

CVSS3: 8.1
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0998-1

больше 1 года назад

Security update for freetype2

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0960-1

больше 1 года назад

Security update for freetype2

EPSS: Средний
rocky логотип

RLSA-2025:3421

около 1 года назад

Important: freetype security update

EPSS: Средний
rocky логотип

RLSA-2025:3407

около 1 года назад

Important: freetype security update

EPSS: Средний
github логотип

GHSA-g8qj-jv5h-78cp

больше 1 года назад

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
EPSS: Средний
oracle-oval логотип

ELSA-2025-3421

больше 1 года назад

ELSA-2025-3421: freetype security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2025-3407

больше 1 года назад

ELSA-2025-3407: freetype security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2025-3395

больше 1 года назад

ELSA-2025-3395: freetype security update (IMPORTANT)

EPSS: Средний
rocky логотип

RLSA-2025:8292

около 1 года назад

Important: mingw-freetype and spice-client-win security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8292

около 1 года назад

ELSA-2025-8292: mingw-freetype and spice-client-win security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-02719

Уязвимость библиотеки для растеризации шрифтов FreeType, связанная с чтением за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
26%
Средний
больше 3 лет назад
redos логотип
ROS-20250722-03

Уязвимость FreeType

CVSS3: 8.1
26%
Средний
около 1 года назад
ubuntu логотип
CVE-2025-27363

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
26%
Средний
больше 1 года назад
redhat логотип
CVE-2025-27363

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
26%
Средний
больше 1 года назад
nvd логотип
CVE-2025-27363

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
26%
Средний
больше 1 года назад
msrc логотип
CVE-2025-27363

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
26%
Средний
больше 1 года назад
debian логотип
CVE-2025-27363

An out of bounds write exists in FreeType versions 2.13.0 and below (n ...

CVSS3: 8.1
26%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0998-1

Security update for freetype2

26%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0960-1

Security update for freetype2

26%
Средний
больше 1 года назад
rocky логотип
RLSA-2025:3421

Important: freetype security update

26%
Средний
около 1 года назад
rocky логотип
RLSA-2025:3407

Important: freetype security update

26%
Средний
около 1 года назад
github логотип
GHSA-g8qj-jv5h-78cp

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVSS3: 8.1
26%
Средний
больше 1 года назад
oracle-oval логотип
ELSA-2025-3421

ELSA-2025-3421: freetype security update (IMPORTANT)

26%
Средний
больше 1 года назад
oracle-oval логотип
ELSA-2025-3407

ELSA-2025-3407: freetype security update (IMPORTANT)

26%
Средний
больше 1 года назад
oracle-oval логотип
ELSA-2025-3395

ELSA-2025-3395: freetype security update (IMPORTANT)

26%
Средний
больше 1 года назад
rocky логотип
RLSA-2025:8292

Important: mingw-freetype and spice-client-win security update

около 1 года назад
oracle-oval логотип
ELSA-2025-8292

ELSA-2025-8292: mingw-freetype and spice-client-win security update (IMPORTANT)

около 1 года назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.