FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c. CREATE(Triage):(User=admin) [CVE-2015-9383|https://nvd.nist.gov/vuln/detail/CVE-2015-9383]