VYPR

Libredwg

by GNU

Source repositories

CVEs (97)

  • CVE-2025-61154MedMar 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.

  • CVE-2021-45950MedJan 1, 2022
    risk 0.42cvss 6.5epss 0.01

    LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

  • CVE-2021-39523MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39521MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.

  • CVE-2020-21839MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.

  • CVE-2020-21835MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.

  • CVE-2020-21834MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.

  • CVE-2020-21817MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).

  • CVE-2020-21815MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).

  • CVE-2020-15807MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.01

    GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.

  • CVE-2019-20909HigJul 16, 2020
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

  • CVE-2020-6615MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.02

    GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

  • CVE-2020-6611MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.02

    GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.

  • CVE-2020-6610MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

  • CVE-2019-20015MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.

  • CVE-2019-20013MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.

  • CVE-2019-20012MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.

  • CVE-2019-20009MedDec 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.

  • CVE-2026-9605HigMay 27, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2020-23861MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.

Page 4 of 5