FontForge is a widely used open-source font-editing application that processes complex binary font file formats from diverse sources, creating a surface for memory-safety issues. The vulnerability pattern is durable and concentrated: recurrent out-of-bounds reads, heap-based buffer overflows, memory-bounds violations, use-after-free conditions, and command-injection flaws reflect the parsing demands of rendering-engine integration and untrusted font-file handling. Defenders should treat FontForge instances processing untrusted fonts as a supply-chain risk vector, particularly in automated font-conversion pipelines and design workflows where malformed or adversarial files may be processed without prior validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fontforge over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15785CRITICAL FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. | Aug 29, 2019 | 9.8 | 30 | NO | NO |
CVE-2025-15270HIGH FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Dec 31, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-15280HIGH FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fon | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15275HIGH FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15274HIGH FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15273HIGH FontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15272HIGH FontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15271HIGH FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-15269HIGH FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fon | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2020-5496HIGH FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c. | Jan 3, 2020 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fontforge.
Media articles that mention a CVE ID that affects a product developed by Fontforge — matched by CVE ID, not by vendor name.