FreeType before 2.6.2 has a heap-based buffer over-read in ttcmap14validate in sfnt/ttcmap.c.
{ "urgency": "not yet assigned" }