FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in FontForge, specifically within the SFD file parsing process. This issue arises from improper validation of user-supplied data, allowing for a write past the end of an allocated array. As a result, remote attackers can execute arbitrary code on affected installations, but user interaction is required to exploit the vulnerability by opening a malicious SFD file.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed in the context of the current user.

Remediation

Due to the nature of this vulnerability, the recommended mitigation strategy is to limit interaction with the product.

Added: Dec 31, 2025, 7:21 AM
Updated: Dec 31, 2025, 7:21 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
4.4
remediation
7.9
relevance
1.8
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.