VYPR

Libredwg

by GNU

Source repositories

CVEs (97)

  • CVE-2020-21836HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.

  • CVE-2020-21833HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.

  • CVE-2020-21832HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.

  • CVE-2020-21830HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.

  • CVE-2020-21819HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.

  • CVE-2020-21818HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.

  • CVE-2020-21816HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.

  • CVE-2020-21814HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.

  • CVE-2019-20914CriJul 16, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.

  • CVE-2020-6609HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.02

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

  • CVE-2019-20014HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.

  • CVE-2019-20011HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.

  • CVE-2019-20010HigDec 27, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.

  • CVE-2020-6614HigJan 8, 2020
    risk 0.53cvss 8.1epss 0.02

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.

  • CVE-2020-6613HigJan 8, 2020
    risk 0.53cvss 8.1epss 0.02

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

  • CVE-2020-6612HigJan 8, 2020
    risk 0.53cvss 8.1epss 0.02

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

  • CVE-2022-45332HigNov 30, 2022
    risk 0.51cvss 7.8epss 0.00

    LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.

  • CVE-2022-33034HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.

  • CVE-2022-33033HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

  • CVE-2022-33032HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.

Page 2 of 5