Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

FontForge — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting FontForge. AI-powered Chinese analysis, POCs, and references for each vulnerability.

FontForge serves as a primary open-source font editor for creating and modifying digital typefaces. Historically, it has been vulnerable to multiple remote code execution flaws due to buffer overflows in parsing font files, along with cross-site scripting vulnerabilities in web-based components and privilege escalation issues through insecure file handling. Notable security characteristics include its C/C++ codebase which has been prone to memory corruption flaws, with 12 documented CVEs including critical RCE vulnerabilities in recent years. The application's complex parsing of various font formats has consistently introduced security risks, making it a target for exploitation through maliciously crafted font files.

Top products by FontForge: FontForge
CVE IDTitleCVSSSeverityPublished
CVE-2025-15279 FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-122 7.8 -2025-12-31
CVE-2025-15278 FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability — FontForgeCWE-190 7.8 -2025-12-31
CVE-2025-15277 FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-122 7.8 -2025-12-31
CVE-2025-15276 FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability — FontForgeCWE-502 7.8 -2025-12-31
CVE-2025-15280 FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability — FontForgeCWE-416 7.8 -2025-12-31
CVE-2025-15275 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-122 7.8 -2025-12-31
CVE-2025-15274 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-122 7.8 -2025-12-31
CVE-2025-15273 FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-121 7.8 -2025-12-31
CVE-2025-15272 FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — FontForgeCWE-122 7.8 -2025-12-31
CVE-2025-15271 FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability — FontForgeCWE-129 7.8 -2025-12-31
CVE-2025-15270 FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability — FontForgeCWE-129 7.8 -2025-12-31
CVE-2025-15269 FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability — FontForgeCWE-416 7.8 -2025-12-31

This page lists every published CVE security advisory associated with FontForge. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.