← Vulnerability feed

Vulnerability record · CVE-2016-10328 · published 14 April 2017

CVE-2016-10328: Freetype out-of-bounds write vulnerability

Freetype · Freetype

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

9.8 CVSS 3.1 Critical EPSS 3.7% · top 10.7% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 7.5
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10328 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2020-15999FreeType heap buffer overflow in Chrome via crafted HTML pageFreeType contains a heap buffer overflow reachable through a crafted HTML page in Google Chrome prior to 86.0.4240.111. The flaw is an out-of-bounds …KEVEPSS 44%analysed8.1CVE-2025-27363FreeType out-of-bounds write in TrueType GX and variable font parsingFreeType 2.13.0 and earlier mishandle font subglyph structures in TrueType GX and variable font files: a signed short is assigned to an unsigned long…KEVEPSS 28%analysed10.0CVE-2015-6015Oracle outside in technology vulnerabilityUnspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to aff…EPSS 8.4%10.0CVE-2015-6014Oracle outside in technology vulnerabilityUnspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to aff…EPSS 8.4%10.0CVE-2015-6013Oracle outside in technology vulnerabilityUnspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to aff…EPSS 8.4%10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2022-27404Freetype out-of-bounds write vulnerabilityFreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.EPSS 2.7%9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%

Source: NIST National Vulnerability Database (record CVE-2016-10328), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.