Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
libredwg vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-26157
Versions of the package libredwg prior to 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
Gnu Libredwg
6.5
CVSSv3
CVE-2019-20911
An issue exists in GNU LibreDWG up to and including 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
Gnu Libredwg
9.8
CVSSv3
CVE-2019-20914
An issue exists in GNU LibreDWG up to and including 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
Gnu Libredwg
6.5
CVSSv3
CVE-2021-45950
LibreDWG 0.12.4.4313 up to and including 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).
Gnu Libredwg
6.5
CVSSv3
CVE-2018-14524
dwg_decode_eed in decode.c in GNU LibreDWG prior to 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.
Gnu Libredwg
6.5
CVSSv3
CVE-2018-14471
dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote malicious users to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
Gnu Libredwg
8.8
CVSSv3
CVE-2021-42585
A heap buffer overflow exists in copy_compressed_bytes in decode_r2007.c in dwgread prior to 0.12.4 via a crafted dwg file.
Gnu Libredwg
8.8
CVSSv3
CVE-2021-42586
A heap buffer overflow exists in copy_bytes in decode_r2007.c in dwgread prior to 0.12.4 via a crafted dwg file.
Gnu Libredwg
8.8
CVSSv3
CVE-2021-36080
GNU LibreDWG 0.12.3.4163 up to and including 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
Gnu Libredwg
7.5
CVSSv3
CVE-2021-28236
LibreDWG v0.12.3 exists to contain a NULL pointer dereference via out_dxfb.c.
Gnu Libredwg 0.12.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »