Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3078 | FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c. |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freetype
Freetype freetype |
|
| CPEs | cpe:2.3:a:freetype:freetype:2.8.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Freetype
Freetype freetype |
Mon, 13 Jan 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 11 Jan 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | freetype: signed integer overflow in cf2_doFlex | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 10 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Fri, 10 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-12T20:31:17.819Z
Reserved: 2025-01-10T00:00:00.000Z
Link: CVE-2025-23022
Updated: 2025-02-12T20:24:47.672Z
Status : Analyzed
Published: 2025-01-10T15:15:16.967
Modified: 2025-01-16T21:12:15.537
Link: CVE-2025-23022
OpenCVE Enrichment
No data.
EUVD