← Vulnerability feed

Vulnerability record · CVE-2025-50951 · published 23 October 2025

CVE-2025-50951: Fontforge memory leak vulnerability

Fontforge · Fontforge

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

6.5 CVSS 3.1 Medium EPSS 0.26% · top 84.1% CWE-401 · Memory leak
6.5CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-50951 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15785Fontforge memory buffer overflow vulnerabilityFontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.EPSS 2.7%8.8CVE-2025-15280Fontforge use after free vulnerabilityFontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…EPSS 0.61%8.8CVE-2025-15271Fontforge vulnerabilityFontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec…EPSS 0.61%8.8CVE-2025-15272Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15273Fontforge stack-based buffer overflow vulnerabilityFontForge PFB File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…EPSS 0.61%8.8CVE-2025-15274Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15275Fontforge heap-based buffer overflow vulnerabilityFontForge SFD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…EPSS 0.61%8.8CVE-2025-15269Fontforge use after free vulnerabilityFontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2025-50951), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.