Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2025-27363KEVEXPLOITEDPATCHED
freetype · freetype

CVE-2025-27363: An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when

Description

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

Affected Products

VendorProductVersions
freetypefreetype0.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
debiandebian_linuxcve_cpe95%
ibmibm app connect enterprisecert_advisory90%
ibmibm infosphere informationcert_advisory90%
oraclecommunicationscert_advisory90%

References

  • https://www.facebook.com/security/advisories/cve-2025-27363(x_refsource_CONFIRM)

Related News (3 articles)

Tier B
BSI Advisories9h ago
[UPDATE] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security114d ago
Re: CVE-2025-27363: FontForge affected by FreeType heap-buffer-overflow; upstream maintainer declines under Community-guidelines #D1
→ No new info (linked only)
Tier C
oss-security118d ago
CVE-2025-27363: FontForge affected by FreeType heap-buffer-overflow; upstream maintainer declines under Community-guidelines #D1
→ No new info (linked only)
CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C/CR:H/IR:H/AR:H/MAV:N/MAC:L/MPR:N/MUI:N/MS:U/MC:H/MI:H/MA:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
2.13.3
PublishedMar 11, 2025
Last enriched118d agov2
Trending Score123🔥
Source articles3
Independent2
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

MEDIUMCVE-2026-50811
CVE-2026-50811: An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 11, 2025
Added to CISA KEV
Mar 11, 2025
Discovered by ZDM
Apr 1, 2026
Updated: affectedVersions, patchAvailable
Apr 16, 2026
Actively Exploited
Apr 19, 2026
Exploit Available
Apr 19, 2026
Patch Available
Apr 19, 2026

Version History

v2
Last enriched 118d ago
v2Tier C118d ago

Updated affected versions to include 2.13.2 and added patch available for version 2.13.3.

affectedVersionspatchAvailable
via oss-security
v1132d ago

Initial creation