CVE-2024-25081
MEDIUM 4.2EPSS 1.1%
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
- CVSS v3.1
- 4.2 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L - EPSS
- 1.08% chance of exploitation in the next 30 days, 63th percentile
- Published
- 2024-02-26
- Updated
- 2025-11-04
Proof-of-concept exploits (3)
- InzegoSec/CVE-2024-25081_2025-47273
- AliElKhatteb/CVE-2024-25082_CVE-2024-25081
- Liquid1998/FontForge-CVES