FreeType is a widely embedded, open-source font-rendering library that processes complex binary font formats across countless applications, web browsers, and operating systems, giving vulnerabilities in this single product an outsized footprint across the software landscape. The vulnerability exposure skews strongly toward critical-severity outcomes, reflecting the memory-safety demands of parsing untrusted font files in performance-critical code paths. The recurring weakness classes—buffer overflows, out-of-bounds reads and writes, and improper bounds checking—are endemic to the library's C-based implementation and its role as a trusted, low-level handler of potentially adversarial input. Defenders should treat FreeType advisories as broadly applicable supply-chain issues and prioritize remediation across systems and applications that bundle the library, since a single flaw can impact millions of downstream endpoints. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freetype over time
Signals from CVEs in this vendor scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15999CRITICAL Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 3, 2020 | 9.6 | 88 | YES | NO |
CVE-2025-27363HIGH An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to Tru | Mar 11, 2025 | 8.1 | 79 | YES | NO |
CVE-2017-8105CRITICAL FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c. | Apr 24, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-7864CRITICAL FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c. | Apr 14, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-7857CRITICAL FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face fu | Apr 14, 2017 | 9.8 | 33 | NO | NO |
CVE-2011-2895HIGH The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in Open | Aug 19, 2011 | 9.3 | 33 | NO | NO |
CVE-2017-8287CRITICAL FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c. | Apr 27, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-7858CRITICAL FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c. | Apr 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2016-10328CRITICAL FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c. | Apr 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2006-2661MEDIUM ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference. | May 30, 2006 | 5.0 | 32 | NO | YES |
Signals from CVEs in this vendor scope (95 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freetype.
Media articles that mention a CVE ID that affects a product developed by Freetype — matched by CVE ID, not by vendor name.