VendorsGNUlibredwg0.9.3.2564
Vulnerabilities

GNU Libredwg 0.9.3.2564

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-6609
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
Published 2020-01-08 · Modified
8.8EPSS 0.018
CVE-2020-6612
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
Published 2020-01-08 · Modified
8.1EPSS 0.017
CVE-2020-6613
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
Published 2020-01-08 · Modified
8.1EPSS 0.017
CVE-2020-6614
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
Published 2020-01-08 · Modified
8.1EPSS 0.017
CVE-2020-6611
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
Published 2020-01-08 · Modified
6.5EPSS 0.015
CVE-2020-6615
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
Published 2020-01-08 · Modified
6.5EPSS 0.015
CVE-2020-6610
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
Published 2020-01-08 · Modified
6.5EPSS 0.014