VYPR

Dia

by GNOME Foundation

CVEs (2)

  • CVE-2026-77658HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data()…

  • CVE-2019-19451MedNov 29, 2019
    risk 0.36cvss 5.5epss 0.00

    When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to…