← Vulnerability feed

Vulnerability record · CVE-2025-15277 · published 31 December 2025

CVE-2025-15277: Fontforge heap-based buffer overflow vulnerability

Fontforge · Fontforge

FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.

7.8 CVSS 3.0 High EPSS 0.29% · top 80.6% CWE-122 · Heap-based buffer overflow
7.8CVSS 3.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of scanlines within SGI files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27920.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-15277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15785Fontforge memory buffer overflow vulnerabilityFontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.EPSS 2.7%8.8CVE-2025-15280Fontforge use after free vulnerabilityFontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…EPSS 0.61%8.8CVE-2025-15271Fontforge vulnerabilityFontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…EPSS 0.61%8.8CVE-2025-15272Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15273Fontforge stack-based buffer overflow vulnerabilityFontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…EPSS 0.61%8.8CVE-2025-15274Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15275Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15269Fontforge use after free vulnerabilityFontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2025-15277), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.