Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2754

24
FAUCET Score

CVE-2007-2754 is an integer signedness error in FreeType 2.3.4 and earlier, specifically in truetype/ttgload.c, which could allow remote attackers to execute arbitrary code. This vulnerability, rated with a CVSS score of 6.8, involves a crafted TTF image with a negative n_points value, leading to an integer overflow and subsequent heap-based buffer overflow, potentially resulting in partial confidentiality, integrity, and availability impacts. Despite its high FAUCET Risk Score of 96/100 and above-average EPSS, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.3.4CPE matchmatch criteria
cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.83%
Probability of exploitation in next 30 days
EPSS Percentile
92.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0583 is in the 91st percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

denopatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
nessuspatch availablevia llm_extracted
Fixed in: 2.2.1
postgresqlpatch availablevia llm_extracted
Fixed in: 2.2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: freetype-0:2.1.9-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: freetype-0:2.0.3-10.el21
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: freetype-0:2.2.1-19.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: freetype-0:2.1.9-10.el4.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: freetype-0:2.0.3-17.el21
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: freetype-0:2.1.4-7.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: freetype-0:2.1.4-12.el3
View patch

Vendor Advisories (5)

redhatCVE-2007-2754Moderate

freetype integer overflow

Apr 27, 2007
denollm-deno-89c7b480eae0541e

Integer overflow and heap-based buffer overflow vulnerability in 3rd party module (freetype)

postgresqlllm-postgresql-4a865e3531e2666a

Integer overflow and heap-based buffer overflow vulnerability in 3rd party module (freetype)

libreofficellm-libreoffice-42a982bda1f69501

Integer overflow and heap-based buffer overflow vulnerability in 3rd party module (freetype)

nessusllm-nessus-e9a3265e97c3e65a

Integer overflow and heap-based buffer overflow vulnerability in 3rd party module (freetype)

References

patches.sgi.com / support/free/security/advisories/20070602-01-P.asc
cvs.savannah.nongnu.org / viewvc/freetype2/src/truetype/ttgload.c
Patch
lists.apple.com / archives/Security-announce/2007/Nov/msg00003.html
lists.apple.com / archives/security-announce/2009/May/msg00002.html
lists.gnu.org / archive/html/freetype-devel/2007-04/msg00041.html
Exploit
osvdb.org / 36509
bugzilla.redhat.com / bugzilla/show_bug.cgi
Exploit
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/25350
secunia.com / advisories/25353
secunia.com / advisories/25386
secunia.com / advisories/25463
secunia.com / advisories/25483
secunia.com / advisories/25609
secunia.com / advisories/25612
secunia.com / advisories/25654
secunia.com / advisories/25705
secunia.com / advisories/25808
secunia.com / advisories/25894
secunia.com / advisories/25905
secunia.com / advisories/26129
secunia.com / advisories/26305
secunia.com / advisories/28298
secunia.com / advisories/30161
secunia.com / advisories/35074
secunia.com / advisories/35200
secunia.com / advisories/35204
secunia.com / advisories/35233
issues.rpath.com / browse/RPL-1390
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11325
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5532
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.apple.com / kb/HT3549
support.avaya.com / elmodocs2/security/ASA-2007-330.htm
redhat.com / archives/fedora-package-announce/2009-May/msg01316.html
redhat.com / archives/fedora-package-announce/2009-May/msg01401.html
debian.org / security/2007/dsa-1302
debian.org / security/2007/dsa-1334
gentoo.org / security/en/glsa/glsa-200705-22.xml
gentoo.org / security/en/glsa/glsa-200707-02.xml
gentoo.org / security/en/glsa/glsa-200805-07.xml
mandriva.com / security/advisories
novell.com / linux/security/advisories/2007_41_freetype2.html
openpkg.com / security/advisories/OpenPKG-SA-2007.018.html
redhat.com / support/errata/RHSA-2007-0403.html
redhat.com / support/errata/RHSA-2009-0329.html
redhat.com / support/errata/RHSA-2009-1062.html
securityfocus.com / archive/1/469463/100/200/threaded
securityfocus.com / archive/1/471286/30/6180/threaded
securityfocus.com / bid/24074
securitytracker.com / id
trustix.org / errata/2007/0019
ubuntu.com / usn/usn-466-1
us-cert.gov / cas/techalerts/TA09-133A.html
US Government Resource
vupen.com / english/advisories/2007/1894
vupen.com / english/advisories/2007/2229
vupen.com / english/advisories/2008/0049
vupen.com / english/advisories/2009/1297