CVE-2018-19876: Cairographics Cairo

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.

Affected products

Published 2018-12-05. Last modified 2026-06-17.