FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Oct 2025 05:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:fontforge:fontforge:2023-01-01:*:*:*:*:*:*:*

Fri, 24 Oct 2025 22:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-401
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 19:30:00 +0900

Type Values Removed Values Added
First Time appeared Fontforge
Fontforge fontforge
Vendors & Products Fontforge
Fontforge fontforge

Fri, 24 Oct 2025 09:15:00 +0900

Type Values Removed Values Added
Title fontforge: Fontforge memory leak
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 24 Oct 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 00:30:00 +0900

Type Values Removed Values Added
Description FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-24T12:55:22.980Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50949

cve-icon Vulnrichment

Updated: 2025-10-23T16:23:55.621Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-23T16:15:49.517

Modified: 2025-10-27T20:18:04.340

Link: CVE-2025-50949

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-23T00:00:00Z

Links: CVE-2025-50949 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-10-24T19:17:09Z

Weaknesses