CVE-2014-9664
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attacke
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
MEDIUM · CVSS 6.8
EPSS 0.01169
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0