fontforge CVE Vulnerabilities & Metrics

Focus on fontforge vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fontforge Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fontforge. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fontforge CVEs: 15
Earliest CVE date: 23 Jul 2017, 22:29 UTC
Latest CVE date: 23 Feb 2021, 04:15 UTC

Latest CVE reference: CVE-2020-25690

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fontforge CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.68

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 14
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS fontforge CVEs

These are the five CVEs with the highest CVSS scores for fontforge, sorted by severity first and recency.

All CVEs for fontforge

CVE-2020-25690 fontforge vulnerability CVSS: 6.8 23 Feb 2021, 04:15 UTC

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-5496 fontforge vulnerability CVSS: 6.8 03 Jan 2020, 22:15 UTC

FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

CVE-2020-5395 fontforge vulnerability CVSS: 6.8 03 Jan 2020, 20:15 UTC

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

CVE-2019-15785 fontforge vulnerability CVSS: 7.5 29 Aug 2019, 13:15 UTC

FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.

CVE-2017-17521 fontforge vulnerability CVSS: 6.8 14 Dec 2017, 16:29 UTC

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

CVE-2017-11577 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11576 fontforge vulnerability CVSS: 4.3 23 Jul 2017, 22:29 UTC

FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.

CVE-2017-11575 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.

CVE-2017-11574 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a heap-based buffer overflow in readcffset (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11573 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11572 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11571 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11570 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11569 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.

CVE-2017-11568 fontforge vulnerability CVSS: 6.8 23 Jul 2017, 22:29 UTC

FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.