Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2015-9383
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2015-9383
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-9383.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-9383
Downstream
DEBIAN-CVE-2015-9383
DLA-1909-1
UBUNTU-CVE-2015-9383
USN-4126-1
USN-4126-2
Published
2019-09-03T05:15:10Z
Modified
2025-08-09T20:01:26Z
Severity
6.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
FreeType before 2.6.2 has a heap-based buffer over-read in tt
cmap14
validate in sfnt/ttcmap.c.
References
https://lists.debian.org/debian-lts-announce/2019/09/msg00002.html
https://savannah.nongnu.org/bugs/?46346
https://usn.ubuntu.com/4126-1/
https://usn.ubuntu.com/4126-2/
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=57cbb8c148999ba8f14ed53435fc071ac9953afd
Affected packages
CVE-2015-9383 - OSV