Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Freetype

First CVE: May 23, 2006Active for: 20 yearsTotal CVEs: 95
67.9
VTI Score
TOP TARGET

FreeType is a widely embedded, open-source font-rendering library that processes complex binary font formats across countless applications, web browsers, and operating systems, giving vulnerabilities in this single product an outsized footprint across the software landscape. The vulnerability exposure skews strongly toward critical-severity outcomes, reflecting the memory-safety demands of parsing untrusted font files in performance-critical code paths. The recurring weakness classes—buffer overflows, out-of-bounds reads and writes, and improper bounds checking—are endemic to the library's C-based implementation and its role as a trusted, low-level handler of potentially adversarial input. Defenders should treat FreeType advisories as broadly applicable supply-chain issues and prioritize remediation across systems and applications that bundle the library, since a single flaw can impact millions of downstream endpoints. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
95
Total CVEs
More Total CVEs than 99% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
2.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Freetype over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2006
20 years ago
Most Recent CVE
Mar 2, 2026
144 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-15999CRITICAL
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 3, 20209.688YESNO
CVE-2025-27363HIGH
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to Tru
Mar 11, 20258.179YESNO
CVE-2017-8105CRITICAL
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
Apr 24, 20179.833NONO
CVE-2017-7864CRITICAL
FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
Apr 14, 20179.833NONO
CVE-2017-7857CRITICAL
FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face fu
Apr 14, 20179.833NONO
CVE-2011-2895HIGH
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in Open
Aug 19, 20119.333NONO
CVE-2017-8287CRITICAL
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
Apr 27, 20179.832NONO
CVE-2017-7858CRITICAL
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
Apr 14, 20179.832NONO
CVE-2016-10328CRITICAL
FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
Apr 14, 20179.832NONO
CVE-2006-2661MEDIUM
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
May 30, 20065.032NOYES
View all 95 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products95 CVEs
41%
48%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (3.2%)
Network18 (18.9%)
Unknown74 (77.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (21.1%)
High1 (1.1%)
Unknown74 (77.9%)
User Interaction
None14 (14.7%)
Unknown74 (77.9%)
Required7 (7.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (22.1%)
Unknown74 (77.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (95 CVEs).

CISA KEV
2 CVEs
2.1% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Freetype.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Freetype — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Freetype's Products

View all 6 CNAs →

Top CWEs