cbcvebase.

Debian Fig2Dev vulnerabilities

32 known vulnerabilities affecting debian/fig2dev.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM19LOW10

Vulnerabilities

Page 1 of 2
CVE-2025-46397P3HIGHCVSS 7.8fixed in fig2dev 1:3.2.8b-3+deb12u2 (bookworm)2025
CVE-2025-46397 [HIGH] CVE-2025-46397: fig2dev - A flaw was found in xfig. This vulnerability allows possible code execution via ... A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u2) bullseye: resolved (fixed in 1:3.2.8-3+deb11u3) forky: resolved (fixed in 1:3.2.9a-4) sid: resolved (fixed in 1:3.2.9a-4) trixie: resolved (fixed in 1:3.2.9a-4)
debian
CVE-2018-16140P3LOWCVSS 7.8fixed in fig2dev 1:3.2.7a-3 (bookworm)2018
CVE-2018-16140 [HIGH] CVE-2018-16140: fig2dev - A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allow... A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. Scope: local bookworm: resolved (fixed in 1:3.2.7a-3) bullseye: resolved (fixed in 1:3.2.7a-3) forky: resolved (fixed in 1:3.2.7a-3) sid: resolved (fixed in 1:3.2.7a-3) trixie: resolved (fixed in 1:3.2.7
debian
CVE-2025-31163P4MEDIUMCVSS 6.6fixed in fig2dev 1:3.2.8b-3+deb12u1 (bookworm)2025
CVE-2025-31163 [MEDIUM] CVE-2025-31163: fig2dev - Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availabili... Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u1) bullseye: resolved (fixed in 1:3.2.8-3+deb11u2) forky: resolved (fixed in 1:3.2.9a-2) sid: resolved (fixed in 1:3.2.9a-2) trixie: resolved (fixed in 1:3.2.9a-2)
debian
CVE-2021-3561P4HIGHCVSS 7.1fixed in fig2dev 1:3.2.8-3 (bookworm)2021
CVE-2021-3561 [HIGH] CVE-2021-3561: fig2dev - An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in... An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability. Scope: local bookworm: resolved (fixed i
debian
CVE-2025-31164P4MEDIUMCVSS 6.6fixed in fig2dev 1:3.2.8b-3+deb12u1 (bookworm)2025
CVE-2025-31164 [MEDIUM] CVE-2025-31164: fig2dev - heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availabi... heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u1) bullseye: resolved (fixed in 1:3.2.8-3+deb11u2) forky: resolved (fixed in 1:3.2.9a-2) sid: resolved (fixed in 1:3.2.9a-2) trixie: resolved (fixed in 1:3.2.9a-2)
debian
CVE-2025-31162P4MEDIUMCVSS 6.6fixed in fig2dev 1:3.2.8b-3+deb12u1 (bookworm)2025
CVE-2025-31162 [MEDIUM] CVE-2025-31162: fig2dev - Floating point exception in fig2dev in version 3.2.9a allows an attacker to avai... Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u1) bullseye: resolved (fixed in 1:3.2.8-3+deb11u2) forky: resolved (fixed in 1:3.2.9a-2) sid: resolved (fixed in 1:3.2.9a-2) trixie: resolved (fixed in 1:3.2.9a-2)
debian
CVE-2025-46398P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8b-3+deb12u2 (bookworm)2025
CVE-2025-46398 [MEDIUM] CVE-2025-46398: fig2dev - In xfig diagramming tool, a stack-overflow while running fig2dev allows memory c... In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u2) bullseye: resolved (fixed in 1:3.2.8-3+deb11u3) forky: resolved (fixed in 1:3.2.9a-4) sid: resolved (fixed in 1:3.2.9a-4) trixie: resolved (fixed in 1:3.2.9a-
debian
CVE-2017-16899P4HIGHCVSS 7.1fixed in fig2dev 1:3.2.6a-5 (bookworm)2017
CVE-2017-16899 [HIGH] CVE-2017-16899: fig2dev - An array index error in the fig2dev program in Xfig 3.2.6a allows remote attacke... An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c. Scope: local bookworm: resolved (fixed in 1:3.2.6a-5) bullseye: resol
debian
CVE-2019-14275P4LOWCVSS 5.5fixed in fig2dev 1:3.2.7a-7 (bookworm)2019
CVE-2019-14275 [MEDIUM] CVE-2019-14275: fig2dev - Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function... Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. Scope: local bookworm: resolved (fixed in 1:3.2.7a-7) bullseye: resolved (fixed in 1:3.2.7a-7) forky: resolved (fixed in 1:3.2.7a-7) sid: resolved (fixed in 1:3.2.7a-7) trixie: resolved (fixed in 1:3.2.7a-7)
debian
CVE-2025-46400P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8b-3+deb12u2 (bookworm)2025
CVE-2025-46400 [MEDIUM] CVE-2025-46400: fig2dev - In xfig diagramming tool, a segmentation fault while running fig2dev allows an a... In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u2) bullseye: resolved (fixed in 1:3.2.8-3+deb11u3) forky: resolved (fixed in 1:3.2.9a-3) sid: resolved (fixed in 1:3.2.9a-3) trixie: resolved (fi
debian
CVE-2025-46399P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8b-3+deb12u2 (bookworm)2025
CVE-2025-46399 [MEDIUM] CVE-2025-46399: fig2dev - A flaw was found in fig2dev. This vulnerability allows availability via local in... A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. Scope: local bookworm: resolved (fixed in 1:3.2.8b-3+deb12u2) bullseye: resolved (fixed in 1:3.2.8-3+deb11u3) forky: resolved (fixed in 1:3.2.9a-4) sid: resolved (fixed in 1:3.2.9a-4) trixie: resolved (fixed in 1:3.2.9a-4)
debian
CVE-2019-19555P4LOWCVSS 5.5fixed in fig2dev 1:3.2.7b-2 (bookworm)2019
CVE-2019-19555 [MEDIUM] CVE-2019-19555: fig2dev - read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overfl... read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. Scope: local bookworm: resolved (fixed in 1:3.2.7b-2) bullseye: resolved (fixed in 1:3.2.7b-2) forky: resolved (fixed in 1:3.2.7b-2) sid: resolved (fixed in 1:3.2.7b-2) trixie: resolved (fixed in 1:3.2.7b-2)
debian
CVE-2020-21529P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8-1 (bookworm)2020
CVE-2020-21529 [MEDIUM] CVE-2020-21529: fig2dev - fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in... fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. Scope: local bookworm: resolved (fixed in 1:3.2.8-1) bullseye: resolved (fixed in 1:3.2.8-1) forky: resolved (fixed in 1:3.2.8-1) sid: resolved (fixed in 1:3.2.8-1) trixie: resolved (fixed in 1:3.2.8-1)
debian
CVE-2019-19797P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.7b-3 (bookworm)2019
CVE-2019-19797 [MEDIUM] CVE-2019-19797: fig2dev - read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. Scope: local bookworm: resolved (fixed in 1:3.2.7b-3) bullseye: resolved (fixed in 1:3.2.7b-3) forky: resolved (fixed in 1:3.2.7b-3) sid: resolved (fixed in 1:3.2.7b-3) trixie: resolved (fixed in 1:3.2.7b-3)
debian
CVE-2020-21533P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.7b-3 (bookworm)2020
CVE-2020-21533 [MEDIUM] CVE-2020-21533: fig2dev - fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function ... fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c. Scope: local bookworm: resolved (fixed in 1:3.2.7b-3) bullseye: resolved (fixed in 1:3.2.7b-3) forky: resolved (fixed in 1:3.2.7b-3) sid: resolved (fixed in 1:3.2.7b-3) trixie: resolved (fixed in 1:3.2.7b-3)
debian
CVE-2019-19746P4LOWCVSS 5.5fixed in fig2dev 1:3.2.7b-3 (bookworm)2019
CVE-2019-19746 [MEDIUM] CVE-2019-19746: fig2dev - make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out... make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. Scope: local bookworm: resolved (fixed in 1:3.2.7b-3) bullseye: resolved (fixed in 1:3.2.7b-3) forky: resolved (fixed in 1:3.2.7b-3) sid: resolved (fixed in 1:3.2.7b-3) trixie: resolved (fixed in 1:3.2.7b-3)
debian
CVE-2020-21676P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8-1 (bookworm)2020
CVE-2020-21676 [MEDIUM] CVE-2020-21676: fig2dev - A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c ... A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format. Scope: local bookworm: resolved (fixed in 1:3.2.8-1) bullseye: resolved (fixed in 1:3.2.8-1) forky: resolved (fixed in 1:3.2.8-1) sid: resolved (fixed in 1:3.2.8-1) tr
debian
CVE-2020-21675P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.7b-3 (bookworm)2020
CVE-2020-21675 [MEDIUM] CVE-2020-21675: fig2dev - A stack-based buffer overflow in the genptk_text component in genptk.c of fig2de... A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format. Scope: local bookworm: resolved (fixed in 1:3.2.7b-3) bullseye: resolved (fixed in 1:3.2.7b-3) forky: resolved (fixed in 1:3.2.7b-3) sid: resolved (fixed in 1:3.2.7b-3) trixie: reso
debian
CVE-2020-21680P4LOWCVSS 5.5fixed in fig2dev 1:3.2.8-1 (bookworm)2020
CVE-2020-21680 [MEDIUM] CVE-2020-21680: fig2dev - A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig... A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format. Scope: local bookworm: resolved (fixed in 1:3.2.8-1) bullseye: resolved (fixed in 1:3.2.8-1) forky: resolved (fixed in 1:3.2.8-1) sid: resolved (fixed in 1:3.2.8-1) trixie: re
debian
CVE-2020-21532P4MEDIUMCVSS 5.5fixed in fig2dev 1:3.2.8-1 (bookworm)2020
CVE-2020-21532 [MEDIUM] CVE-2020-21532: fig2dev - fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in g... fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c. Scope: local bookworm: resolved (fixed in 1:3.2.8-1) bullseye: resolved (fixed in 1:3.2.8-1) forky: resolved (fixed in 1:3.2.8-1) sid: resolved (fixed in 1:3.2.8-1) trixie: resolved (fixed in 1:3.2.8-1)
debian
Debian Fig2Dev vulnerabilities | cvebase