Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Otfcc Project

First CVE: Dec 30, 2018Active for: 8 yearsTotal CVEs: 88
25.7
VTI Score
Low

Otfcc is a specialized font-compilation and OpenType toolchain project with a narrow product scope but prominent presence in font-processing supply chains. The project's vulnerability footprint concentrates in its single otfcc utility and recurs through memory-safety and bounds-checking weakness classes—out-of-bounds reads and writes, buffer-boundary violations, and insufficient validation of exceptional conditions—that are characteristic of low-level binary file parsing. Font parsers operate on untrusted input streams across a wide range of design, publishing, and rendering workflows, making memory-safety issues in this layer a structural concern even at modest volume. Defenders should track this vendor's releases when font processing is part of the threat model and treat parsing-oriented flaws as warranting prompt review; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
88
Total CVEs
More Total CVEs than 99% of tracked vendors
44.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Otfcc Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2018
7 years ago
Most Recent CVE
Oct 14, 2022
1,379 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (88 CVEs).

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-33047CRITICAL
OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
Jul 6, 20229.832NONO
CVE-2022-35050MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.
Oct 14, 20226.523NONO
CVE-2022-35049MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b03b5.
Oct 14, 20226.523NONO
CVE-2022-35047MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b05aa.
Oct 14, 20226.523NONO
CVE-2022-35046MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0466.
Oct 14, 20226.523NONO
CVE-2022-35045MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0d63.
Oct 14, 20226.523NONO
CVE-2022-35044MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x617087.
Oct 14, 20226.523NONO
CVE-2022-35043MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c08a6.
Oct 14, 20226.523NONO
CVE-2022-35042MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adb11.
Oct 14, 20226.523NONO
CVE-2022-35041MEDIUM
OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b558f.
Oct 14, 20226.523NONO
View all 88 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products88 CVEs
99%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network88 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (1.1%)
Unknown0 (0.0%)
Required87 (98.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None88 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (88 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Otfcc Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Otfcc Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Otfcc Project's Products

View all 1 CNAs →

Top CWEs