Vendorsfontconfig projectfontconfigany version
Vulnerabilities

fontconfig project fontconfig any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2016-5384
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
Published 2016-08-12 · Modified
7.8EPSS 0.004