CVE-2014-2240: FreeType

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.

Affected products

  • FreeType FreeType: up to and including 2.5.2; version 1.3.1 only; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; …

Published 2014-03-12. Last modified 2026-06-17.