Loading
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Use CWE-787, Nothings vendor hub and Stb Truetype.H product page to widen CVE-2022-25515 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-6623, CVE-2020-6622 and CVE-2020-6621 for nearby disclosures in the same product family.