Loading
The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
Use CWE-125, Freetype vendor hub and Freetype product page to widen CVE-2016-10244 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-15999, CVE-2025-27363 and CVE-2022-27404 for nearby disclosures in the same product family.