Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xfig xfig vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2020-21684
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into pict2e format.
Fig2dev Project Fig2dev 3.2.7b
4.3
CVSSv2
CVE-2020-21681
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into ge format.
Fig2dev Project Fig2dev 3.2.7b
4.3
CVSSv2
CVE-2020-21683
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into pstricks format.
Fig2dev Project Fig2dev 3.2.7b
4.3
CVSSv2
CVE-2020-21678
A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into mp format.
Fig2dev Project Fig2dev 3.2.7b
4.3
CVSSv2
CVE-2020-21675
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into ptk format.
Fig2dev Project Fig2dev 3.2.7b
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2020-21676
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into pstricks format.
Fig2dev Project Fig2dev 3.2.7b
Debian Debian Linux 9.0
Debian Debian Linux 10.0
4.3
CVSSv2
CVE-2020-21680
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows malicious users to cause a denial of service (DOS) via converting a xfig file into pict2e format.
Fig2dev Project Fig2dev 3.2.7b
NA
CVE-2023-45920
Xfig v3.2.8 exists to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3