VendorsGNUlibredwgall versions
Vulnerabilities

GNU Libredwg

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2020-6614
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
Published 2020-01-08 · Modified
8.1EPSS 0.017
CVE-2019-20913
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
Published 2020-07-16 · Modified
8.1EPSS 0.012
CVE-2019-20915
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
Published 2020-07-16 · Modified
8.1EPSS 0.012
CVE-2019-20910
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
Published 2020-07-16 · Modified
8.1EPSS 0.012
CVE-2020-21827
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.
Published 2021-05-17 · Modified
7.8EPSS 0.009
CVE-2020-21813
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
Published 2021-05-17 · Modified
7.8EPSS 0.008
CVE-2022-33025
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
Published 2022-06-22 · Modified
7.8EPSS 0.008
CVE-2022-33027
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
Published 2022-06-22 · Modified
7.8EPSS 0.008
CVE-2022-33032
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
Published 2022-06-22 · Modified
7.8EPSS 0.007
CVE-2022-33033
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
Published 2022-06-22 · Modified
7.8EPSS 0.007
CVE-2022-33034
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
Published 2022-06-22 · Modified
7.8EPSS 0.007
CVE-2022-33026
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
Published 2022-06-22 · Modified
7.8EPSS 0.007
CVE-2022-33028
LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
Published 2022-06-22 · Modified
7.8EPSS 0.007
CVE-2022-45332
LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.
Published 2022-11-30 · Modified
7.8EPSS 0.003
CVE-2019-9770
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
Published 2019-03-14 · Modified
7.5EPSS 0.029
CVE-2019-9773
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
Published 2019-03-14 · Modified
7.5EPSS 0.029
CVE-2019-9771
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-9772
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-9776
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-9777
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-9778
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-9779
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
Published 2019-03-14 · Modified
7.5EPSS 0.028
CVE-2019-20909
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
Published 2020-07-16 · Modified
7.5EPSS 0.016
CVE-2021-28236
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
Published 2021-12-02 · Modified
7.5EPSS 0.012
CVE-2022-33024
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
Published 2022-06-22 · Modified
7.5EPSS 0.011
CVE-2023-26157
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
Published 2024-01-02 · Modified
7.5EPSS 0.005
CVE-2020-6611
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
Published 2020-01-08 · Modified
6.5EPSS 0.015
CVE-2020-6615
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
Published 2020-01-08 · Modified
6.5EPSS 0.015
CVE-2020-15807
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
Published 2020-07-17 · Modified
6.5EPSS 0.015
CVE-2019-20009
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
Published 2019-12-27 · Modified
6.5EPSS 0.014
CVE-2019-20013
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
Published 2019-12-27 · Modified
6.5EPSS 0.014
CVE-2020-6610
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
Published 2020-01-08 · Modified
6.5EPSS 0.014
CVE-2019-20015
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
Published 2019-12-27 · Modified
6.5EPSS 0.014
CVE-2019-20012
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
Published 2019-12-27 · Modified
6.5EPSS 0.014
CVE-2018-14471
dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
Published 2018-07-20 · Modified
6.5EPSS 0.014
CVE-2018-14443
get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
Published 2018-07-20 · Modified
6.5EPSS 0.011
CVE-2018-14524
dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.
Published 2018-07-23 · Modified
6.5EPSS 0.011
CVE-2019-20911
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
Published 2020-07-16 · Modified
6.5EPSS 0.010
CVE-2020-21839
An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.
Published 2021-05-17 · Modified
6.5EPSS 0.009
CVE-2020-21815
A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).
Published 2021-05-17 · Modified
6.5EPSS 0.009
← Prev2 / 3Next →