← Vulnerability feed

Vulnerability record · CVE-2006-0747 · published 23 May 2006

CVE-2006-0747: Freetype vulnerability

Freetype · Freetype

Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.

5.0 CVSS 2.0 Medium EPSS 13% · top 3.9% CWE-189 · CWE-189
5.0CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
58References
16 Jun 2026Last modified by NVD

Description

Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html
http://secunia.com/advisories/20525 Vendor Advisory
http://secunia.com/advisories/20591 Vendor Advisory
http://secunia.com/advisories/20638 Vendor Advisory
http://secunia.com/advisories/20791 Vendor Advisory
http://secunia.com/advisories/21062 Vendor Advisory
http://secunia.com/advisories/21135 Vendor Advisory
http://secunia.com/advisories/21385 Vendor Advisory
http://secunia.com/advisories/21701 Vendor Advisory
http://secunia.com/advisories/23939 Vendor Advisory
http://secunia.com/advisories/35074 Vendor Advisory
http://securitytracker.com/id?1016522
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102705-1
http://support.apple.com/kb/HT3549
http://support.avaya.com/elmodocs2/security/ASA-2006-176.htm
http://www.debian.org/security/2006/dsa-1095
http://www.mandriva.com/security/advisories?name=MDKSA-2006:099
http://www.redhat.com/support/errata/RHSA-2006-0500.html
http://www.securityfocus.com/archive/1/436836/100/0/threaded
http://www.securityfocus.com/bid/18326
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0381 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1297 Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183676 Patch
https://issues.rpath.com/browse/RPL-429
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9508
https://usn.ubuntu.com/291-1/
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0012.html
http://secunia.com/advisories/20525 Vendor Advisory
http://secunia.com/advisories/20591 Vendor Advisory
http://secunia.com/advisories/20638 Vendor Advisory
http://secunia.com/advisories/20791 Vendor Advisory
http://secunia.com/advisories/21062 Vendor Advisory
http://secunia.com/advisories/21135 Vendor Advisory
http://secunia.com/advisories/21385 Vendor Advisory
http://secunia.com/advisories/21701 Vendor Advisory

Track CVE-2006-0747 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2020-15999FreeType heap buffer overflow in Chrome via crafted HTML pageFreeType contains a heap buffer overflow reachable through a crafted HTML page in Google Chrome prior to 86.0.4240.111. The flaw is an out-of-bounds …KEVEPSS 44%analysed8.1CVE-2025-27363FreeType out-of-bounds write in TrueType GX and variable font parsingFreeType 2.13.0 and earlier mishandle font subglyph structures in TrueType GX and variable font files: a signed short is assigned to an unsigned long…KEVEPSS 28%analysed10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2022-27404Freetype out-of-bounds write vulnerabilityFreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.EPSS 2.7%9.8CVE-2015-9290Freetype out-of-bounds read vulnerabilityIn FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of…EPSS 2.7%9.8CVE-2017-8287Freetype memory buffer overflow vulnerabilityFreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in ps…EPSS 3.6%9.8CVE-2017-8105Freetype out-of-bounds write vulnerabilityFreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function i…EPSS 4.4%9.8CVE-2016-10328Freetype out-of-bounds write vulnerabilityFreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2006-0747), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.