Synced 17 Jun 2026 06:32 UTC Account
← FreeType

FreeType vulnerabilities: known CVEs & security history

FreeType · Actively exploited · 95 tracked CVEs · 2 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all FreeType release lines — 95 in total, with 2 actively exploited in the wild. A CVE here doesn't mean your version is affected — check FreeType's current status and the safe version to run.

95
known CVEs
2
actively exploited (KEV)
10
critical severity
0
ransomware-linked

Known FreeType CVEs

Actively-exploited and most-severe first. Showing the top 80 of 95. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2020-15999⚡ exploited critical 9.6 44% 2020
CVE-2025-27363⚡ exploited high 8.1 23% 2025
CVE-2022-27404 critical 9.8 3% 2022
CVE-2015-9290 critical 9.8 3% 2019
CVE-2017-8287 critical 9.8 3% 2017
CVE-2017-8105 critical 9.8 4% 2017
CVE-2017-7864 critical 9.8 4% 2017
CVE-2017-7858 critical 9.8 3% 2017
CVE-2017-7857 critical 9.8 4% 2017
CVE-2016-10328 critical 9.8 4% 2017
CVE-2014-9746 critical 9.8 3% 2016
CVE-2012-1126 high 10 6% 2012
CVE-2012-1144 high 9.3 5% 2012
CVE-2012-1142 high 9.3 4% 2012
CVE-2012-1141 high 9.3 4% 2012
CVE-2012-1140 high 9.3 4% 2012
CVE-2012-1139 high 9.3 4% 2012
CVE-2012-1138 high 9.3 5% 2012
CVE-2012-1137 high 9.3 4% 2012
CVE-2012-1136 high 9.3 4% 2012
CVE-2012-1135 high 9.3 5% 2012
CVE-2012-1134 high 9.3 5% 2012
CVE-2012-1133 high 9.3 5% 2012
CVE-2012-1132 high 9.3 4% 2012
CVE-2012-1131 high 9.3 4% 2012
CVE-2012-1130 high 9.3 4% 2012
CVE-2012-1129 high 9.3 4% 2012
CVE-2012-1128 high 9.3 5% 2012
CVE-2012-1127 high 9.3 4% 2012
CVE-2011-2895 high 9.3 8% 2011
CVE-2011-0226 high 9.3 7% 2011
CVE-2010-3311 high 9.3 7% 2011
CVE-2015-9381 high 8.8 2% 2019
CVE-2016-10244 high 7.8 3% 2017
CVE-2022-27406 high 7.5 2% 2022
CVE-2022-27405 high 7.5 2% 2022
CVE-2014-9747 high 7.5 3% 2016
CVE-2014-9674 high 7.5 6% 2015
CVE-2014-9668 high 7.5 2% 2015
CVE-2014-9665 high 7.5 5% 2015
CVE-2014-9663 high 7.5 5% 2015
CVE-2014-9662 high 7.5 4% 2015
CVE-2014-9661 high 7.5 4% 2015
CVE-2014-9660 high 7.5 5% 2015
CVE-2014-9659 high 7.5 8% 2015
CVE-2014-9658 high 7.5 5% 2015
CVE-2014-9657 high 7.5 5% 2015
CVE-2014-9656 high 7.5 5% 2015
CVE-2014-2240 high 7.5 6% 2014
CVE-2009-0946 high 7.5 9% 2009
CVE-2008-1806 high 7.5 4% 2008
CVE-2008-1807 high 7.5 4% 2008
CVE-2008-1808 high 7.5 4% 2008
CVE-2007-3506 high 7.5 2% 2007
CVE-2006-3467 high 7.5 4% 2006
CVE-2006-1861 high 7.5 5% 2006
CVE-2014-9673 medium 6.8 3% 2015
CVE-2014-9669 medium 6.8 4% 2015
CVE-2014-9667 medium 6.8 3% 2015
CVE-2014-9666 medium 6.8 4% 2015
CVE-2014-9664 medium 6.8 4% 2015
CVE-2014-2241 medium 6.8 2% 2014
CVE-2010-3855 medium 6.8 5% 2010
CVE-2010-3814 medium 6.8 4% 2010
CVE-2010-2808 medium 6.8 5% 2010
CVE-2010-2807 medium 6.8 4% 2010
CVE-2010-2806 medium 6.8 6% 2010
CVE-2010-2805 medium 6.8 5% 2010
CVE-2010-2541 medium 6.8 5% 2010
CVE-2010-2527 medium 6.8 6% 2010
CVE-2010-2519 medium 6.8 6% 2010
CVE-2010-2500 medium 6.8 5% 2010
CVE-2010-2499 medium 6.8 6% 2010
CVE-2010-2498 medium 6.8 6% 2010
CVE-2010-2497 medium 6.8 6% 2010
CVE-2007-2754 medium 6.8 6% 2007
CVE-2015-9383 medium 6.5 2% 2019
CVE-2015-9382 medium 6.5 2% 2019
CVE-2018-6942 medium 6.5 2% 2018
CVE-2014-9672 medium 5.8 5% 2015

15 older / lower-severity CVEs not shown — see FreeType's full record.

Is my FreeType version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your FreeType version → · Monitor FreeType for new CVEs →

FreeType vulnerabilities — frequently asked

How many known vulnerabilities does FreeType have?

IsItPatched tracks 95 CVEs for FreeType, 2 of which are actively exploited (CISA KEV). 10 are critical-severity and 46 high-severity. These span every release line — what matters is whether the version you run is affected.

Does FreeType have any actively-exploited vulnerabilities?

Yes — 2 FreeType CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild. Patch these as a priority.

What is the most severe FreeType vulnerability?

Among tracked issues, CVE-2020-15999 (CRITICAL, CVSS 9.6), which is actively exploited, ranks highest — a Out-of-bounds write weakness.

Is FreeType safe to use?

It depends on the version. The latest supported FreeType release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: FreeType security status · FreeType end-of-life · actively-exploited CVEs. Always verify against FreeType's advisories — see our disclaimer.