Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Michel Lind

#33574of 56,330
8.1Total CVSS
Vulnerabilities · 1
PT-2025-10753
8.1
2023-03-18
Freetype · Freetype · CVE-2025-27363
**Name of the Vulnerable Software and Affected Versions** FreeType versions 2.13.0 and below **Description** FreeType is a free, high-quality, portable font engine. A vulnerability exists in versions 2.13.0 and below due to an out-of-bounds write when parsing font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long, causing a buffer overflow and potentially leading to arbitrary code execution. This vulnerability has been actively exploited in the wild and affects Android systems, as well as potentially other platforms utilizing the FreeType library. The vulnerability has been assigned CVE-2025-27363. **Recommendations** Upgrade to a version of FreeType newer than 2.13.0.