Buffer Over-read Vulnerability in FreeType Affects Multiple Versions
CVE-2015-9290
9.8CRITICAL
What is CVE-2015-9290?
A buffer over-read vulnerability exists in FreeType prior to version 2.6.1 that stems from inadequate validation of the cur and limit parameters within the T1_Get_Private_Dict function in the type1/t1parse.c file. This flaw could potentially allow attackers to read beyond the allocated memory buffer, leading to information disclosure or application crashes under certain conditions.