← Vulnerability feed

Vulnerability record · CVE-2012-1130 · published 25 April 2012

CVE-2012-1130: Freetype memory buffer overflow vulnerability

Freetype · Freetype

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.

9.3 CVSS 2.0 High EPSS 3.8% · top 10.5% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
46References
16 Jun 2026Last modified by NVD

Description

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property data in a PCF font.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.html
http://rhn.redhat.com/errata/RHSA-2012-0467.html
http://secunia.com/advisories/48508
http://secunia.com/advisories/48758
http://secunia.com/advisories/48797
http://secunia.com/advisories/48822
http://secunia.com/advisories/48918
http://secunia.com/advisories/48951
http://secunia.com/advisories/48973
http://security.gentoo.org/glsa/glsa-201204-04.xml
http://support.apple.com/kb/HT5503
http://www.mandriva.com/security/advisories?name=MDVSA-2012:057
http://www.mozilla.org/security/announce/2012/mfsa2012-21.html Vendor Advisory
http://www.openwall.com/lists/oss-security/2012/03/06/16
http://www.securityfocus.com/bid/52318
http://www.securitytracker.com/id?1026765
http://www.ubuntu.com/usn/USN-1403-1
https://bugzilla.mozilla.org/show_bug.cgi?id=733512
https://bugzilla.redhat.com/show_bug.cgi?id=800587
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00015.html
http://rhn.redhat.com/errata/RHSA-2012-0467.html
http://secunia.com/advisories/48508
http://secunia.com/advisories/48758
http://secunia.com/advisories/48797
http://secunia.com/advisories/48822
http://secunia.com/advisories/48918
http://secunia.com/advisories/48951
http://secunia.com/advisories/48973
http://security.gentoo.org/glsa/glsa-201204-04.xml
http://support.apple.com/kb/HT5503
http://www.mandriva.com/security/advisories?name=MDVSA-2012:057
http://www.mozilla.org/security/announce/2012/mfsa2012-21.html Vendor Advisory

Track CVE-2012-1130 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed9.6CVE-2020-15999FreeType heap buffer overflow in Chrome via crafted HTML pageFreeType contains a heap buffer overflow reachable through a crafted HTML page in Google Chrome prior to 86.0.4240.111. The flaw is an out-of-bounds …KEVEPSS 44%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed8.1CVE-2025-27363FreeType out-of-bounds write in TrueType GX and variable font parsingFreeType 2.13.0 and earlier mishandle font subglyph structures in TrueType GX and variable font files: a signed short is assigned to an unsigned long…KEVEPSS 28%analysed10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2026-84135Mozilla firefox mobile improper input validation vulnerabilityOther issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.EPSS 0.45%9.8CVE-2023-49060Mozilla firefox mobile vulnerabilityAn attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne…EPSS 0.64%9.8CVE-2022-27404Freetype out-of-bounds write vulnerabilityFreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2012-1130), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.