CRITICAL 9.8 Microsoft
CVE-2022-27404
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Microsoft Security Update 2022-Apr: FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Affected Products
- cm1 freetype 2.11.1-2 on CBL Mariner 1.0
- cbl2 qt5-qtbase 5.15.9-1 on CBL Mariner 2.0
- cbl2 freetype 2.11.1-2 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-27404
- https://nvd.nist.gov/vuln/detail/CVE-2022-27404
This critical severity vulnerability with a CVSS score of 9.8 was published on 2022-04-12 via Microsoft. Affected: cm1 freetype 2.11.1-2 on CBL Mariner 1.0, cbl2 qt5-qtbase 5.15.9-1 on CBL Mariner 2.0, cbl2 freetype 2.11.1-2 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2022-04-12 · 1591 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-27404NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2022-27404Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-43267 PoC | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. | CRITICAL | 9.8 |
| CVE-2020-11984 PoC | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible | CRITICAL | 9.8 |
| CVE-2021-43523 | In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters i | CRITICAL | 9.6 |
| CVE-2023-25725 PoC | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers | CRITICAL | 9.1 |
| CVE-2021-4206 | A flaw was found in the QXL display device emulation in QEMU. An integer overflo | HIGH | 8.2 |
| CVE-2021-4207 | A flaw was found in the QXL display device emulation in QEMU. A double fetch of | HIGH | 8.2 |
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.