{"id":"JLSEC-2025-14","summary":"cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free func...","details":"cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a \"free(): invalid pointer\" error.","modified":"2025-11-06T23:02:28.615696Z","published":"2025-10-10T13:22:08.213Z","upstream":["CVE-2018-19876"],"database_specific":{"sources":[{"published":"2018-12-05T20:29:00.240Z","imported":"2025-10-09T21:00:34.748Z","modified":"2024-11-21T03:58:44.027Z","id":"CVE-2018-19876","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19876","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2018-19876"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://bugs.webkit.org/show_bug.cgi?id=191595"},{"type":"WEB","url":"https://gitlab.freedesktop.org/cairo/cairo/merge_requests/5"}],"affected":[{"package":{"name":"Cairo_jll","ecosystem":"Julia","purl":"pkg:julia/Cairo_jll?uuid=83423d85-b0ee-5818-9007-b63ccbeb887a"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.16.0+0"},{"fixed":"1.18.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-14.json"}}],"schema_version":"1.7.3"}