CVE-2010-2805
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain positio
The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
MEDIUM · CVSS 6.8
EPSS 0.03267
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0