VYPR
Unrated severityNVD Advisory· Published Oct 5, 2005· Updated Apr 16, 2026

CVE-2005-2966

CVE-2005-2966

Description

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.

Affected products

4
  • Dia/Dia4 versions
    cpe:2.3:a:dia:dia:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:dia:dia:*:*:*:*:*:*:*:*range: <=0.94
    • cpe:2.3:a:dia:dia:0.91:*:*:*:*:*:*:*
    • cpe:2.3:a:dia:dia:0.92.2:*:*:*:*:*:*:*
    • cpe:2.3:a:dia:dia:0.93:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.