Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Harfbuzz Project

First CVE: Jan 25, 2016Active for: 10 yearsTotal CVEs: 8

Harfbuzz is a text-shaping library embedded across a wide range of applications and rendering engines to handle complex typographic layouts, making it a foundational component despite its narrow direct product scope. Its recurring vulnerability classes—resource exhaustion, buffer-boundary issues, integer overflow, and NULL-pointer dereferences—reflect the parsing and memory-management demands inherent to processing untrusted font data and complex script-specific shaping rules. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Harfbuzz Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2016
10 years ago
Most Recent CVE
Jan 10, 2026
195 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-56732HIGH
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
Dec 27, 20248.828NONO
CVE-2016-2052HIGH
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other imp
Jan 25, 20167.627NONO
CVE-2023-25193HIGH
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching
Feb 4, 20237.525NONO
CVE-2021-45931MEDIUM
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
Jan 1, 20226.523NONO
CVE-2026-22693MEDIUM
HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-
Jan 10, 20265.322NONO
CVE-2022-33068MEDIUM
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Jun 23, 20225.520NONO
CVE-2015-8947HIGH
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted da
Jul 19, 20167.620NONO
CVE-2015-9274MEDIUM
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to
Nov 15, 20186.518NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (25.0%)
Unknown0 (0.0%)
Required6 (75.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Harfbuzz Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Harfbuzz Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Harfbuzz Project's Products

View all 3 CNAs →

Top CWEs