CVE-2020-25690
CVE-2020-25690
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
23 fev 2021Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allocated on the heap, causing the application to crash or execute arbitrary code. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Produtos afetados
n/a · fontforgeQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →