← Vulnerability feed

Vulnerability record · CVE-2014-2240 · published 12 March 2014

CVE-2014-2240: Freetype memory buffer overflow vulnerability

Freetype · Freetype

Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.

7.5 CVSS 2.0 High EPSS 6.9% · top 6.2% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2020-15999FreeType heap buffer overflow in Chrome via crafted HTML pageFreeType contains a heap buffer overflow reachable through a crafted HTML page in Google Chrome prior to 86.0.4240.111. The flaw is an out-of-bounds …KEVEPSS 44%analysed8.1CVE-2025-27363FreeType out-of-bounds write in TrueType GX and variable font parsingFreeType 2.13.0 and earlier mishandle font subglyph structures in TrueType GX and variable font files: a signed short is assigned to an unsigned long…KEVEPSS 28%analysed10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2022-27404Freetype out-of-bounds write vulnerabilityFreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.EPSS 2.7%9.8CVE-2015-9290Freetype out-of-bounds read vulnerabilityIn FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of…EPSS 2.7%9.8CVE-2017-8287Freetype memory buffer overflow vulnerabilityFreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in ps…EPSS 3.6%9.8CVE-2017-8105Freetype out-of-bounds write vulnerabilityFreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function i…EPSS 4.4%9.8CVE-2016-10328Freetype out-of-bounds write vulnerabilityFreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2014-2240), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.