Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-1861

26
FAUCET Score

CVE-2006-1861 describes multiple integer overflow vulnerabilities in FreeType versions prior to 2.2, affecting components like bdf/bdflib.c, sfnt/ttcmap.c, cff/cffgload.c, and base/ftmac.c. These flaws, including one originally identified as CVE-2006-2493, could allow remote attackers to trigger a denial of service (crash) and potentially execute arbitrary code. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P), it indicates a high severity, network-exploitable vulnerability with low attack complexity, leading to potential partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.0.9CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:2.0.9:*:*:*:*:*:*:*
2.1.3CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:2.1.3:*:*:*:*:*:*:*
2.1.4CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:2.1.4:*:*:*:*:*:*:*
2.1.5CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:2.1.5:*:*:*:*:*:*:*
2.1.6CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:2.1.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.85%
Probability of exploitation in next 30 days
EPSS Percentile
91.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0485 is in the 84th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: freetype-0:2.0.3-17.el21
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: freetype-0:2.1.4-4.0.rhel3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: freetype-0:2.1.4-12.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: freetype-0:2.1.9-1.rhel4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: freetype-0:2.1.9-10.el4.7
View patch

Vendor Advisories (1)

redhatCVE-2006-1861Moderate

freetype: multiple integer overflow vulnerabilities

May 15, 2006

References

patches.sgi.com / support/free/security/advisories/20060701-01-U
lists.apple.com / archives/security-announce/2009/Feb/msg00000.html
lists.opensuse.org / opensuse-security-announce/2007-10/msg00006.html
lists.suse.com / archive/suse-security-announce/2006-Jun/0012.html
bugzilla.redhat.com / bugzilla/attachment.cgi
bugzilla.redhat.com / bugzilla/show_bug.cgi
bugzilla.redhat.com / bugzilla/show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/20100
PatchVendor Advisory
secunia.com / advisories/20525
Vendor Advisory
secunia.com / advisories/20591
Vendor Advisory
secunia.com / advisories/20638
Vendor Advisory
secunia.com / advisories/20791
Vendor Advisory
secunia.com / advisories/21000
Vendor Advisory
secunia.com / advisories/21062
Vendor Advisory
secunia.com / advisories/21135
Vendor Advisory
secunia.com / advisories/21385
Vendor Advisory
secunia.com / advisories/21701
Vendor Advisory
secunia.com / advisories/23939
Vendor Advisory
secunia.com / advisories/27162
Vendor Advisory
secunia.com / advisories/27167
Vendor Advisory
secunia.com / advisories/27271
Vendor Advisory
secunia.com / advisories/33937
Vendor Advisory
secunia.com / advisories/35200
Vendor Advisory
secunia.com / advisories/35204
Vendor Advisory
secunia.com / advisories/35233
Vendor Advisory
security.gentoo.org / glsa/glsa-200607-02.xml
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/26553
issues.rpath.com / browse/RPL-429
sourceforge.net / project/shownotes.php
Patch
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9124
sunsolve.sun.com / search/document.do
support.apple.com / kb/HT3438
support.avaya.com / elmodocs2/security/ASA-2006-176.htm
usn.ubuntu.com / 291-1
redhat.com / archives/fedora-package-announce/2009-May/msg01316.html
redhat.com / archives/fedora-package-announce/2009-May/msg01401.html
debian.org / security/2006/dsa-1095
gentoo.org / security/en/glsa/glsa-200710-09.xml
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2006-0500.html
redhat.com / support/errata/RHSA-2009-0329.html
Vendor Advisory
redhat.com / support/errata/RHSA-2009-1062.html
Vendor Advisory
securityfocus.com / archive/1/436836/100/0/threaded
securityfocus.com / bid/18034
Patch
vupen.com / english/advisories/2006/1868
Vendor Advisory
vupen.com / english/advisories/2007/0381
Vendor Advisory