FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
📦
firefox_mobile
Vendor: mozilla
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
63
Total Indexed
Avg. EPSS
3.48%
Exploit Prob.
Security Vulnerability Index
Page 3 / 7
9.3
CVSS
Severity: HIGH
9.3
CVSS
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted glyph or bitmap data in a BDF font.
Severity: HIGH
10.0
CVSS
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a BDF font.
Severity: HIGH