The TrueType Project maintains a font-rendering implementation that, despite minimal disclosure volume, sits within the rendering pipeline of numerous applications and systems. Its exposure centers on uninitialized-resource handling within the font parser, a structural weakness class characteristic of binary format processing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Truetype Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28030HIGH An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Ta | Mar 5, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Truetype Project.
Media articles that mention a CVE ID that affects a product developed by Truetype Project — matched by CVE ID, not by vendor name.