Debian Gtkwave vulnerabilities
82 known vulnerabilities affecting debian/gtkwave.
Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82
Vulnerabilities
Page 1 of 5
CVE-2023-35961P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35961 [HIGH] CVE-2023-35961: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in `vcd_recorder_main`.
Scope: local
bookworm: resolved (fixed in 3.3.
debian
CVE-2023-35959P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35959 [HIGH] CVE-2023-35959: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns `.ghw` decompression.
Scope: local
bookworm: resolved (fixed in 3.3.118-0.1~deb12u1)
debian
CVE-2023-35963P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35963 [HIGH] CVE-2023-35963: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt2` utility.
Scope: local
bookworm: resolved (fixed in 3
debian
CVE-2023-35962P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35962 [HIGH] CVE-2023-35962: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2vzt` utility.
Scope: local
bookworm: resolved (fixed in 3.
debian
CVE-2023-35964P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35964 [HIGH] CVE-2023-35964: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt` utility.
Scope: local
bookworm: resolved (fixed in 3.
debian
CVE-2023-35960P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35960 [HIGH] CVE-2023-35960: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio...
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns legacy decompression in `vcd_main`.
Scope: local
bookworm: resolved (fixed in 3.3.11
debian
CVE-2023-39234P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39234 [HIGH] CVE-2023-39234: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_blo...
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when looping over `lt->numrealfacs`.
Scope:
debian
CVE-2023-37419P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37419 [HIGH] CVE-2023-37419: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ...
Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt2 conversion util
debian
CVE-2023-37420P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37420 [HIGH] CVE-2023-37420: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ...
Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utili
debian
CVE-2023-38649P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38649 [HIGH] CVE-2023-38649: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname...
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.
Scope:
debian
CVE-2023-38648P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38648 [HIGH] CVE-2023-38648: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname...
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop.
Scope:
debian
CVE-2023-37418P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37418 [HIGH] CVE-2023-37418: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ...
Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utili
debian
CVE-2023-39235P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39235 [HIGH] CVE-2023-39235: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_blo...
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when looping over `lt->num_time_ticks`.
Scop
debian
CVE-2023-37417P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37417 [HIGH] CVE-2023-37417: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ...
Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's interactive VCD pa
debian
CVE-2023-37416P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37416 [HIGH] CVE-2023-37416: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ...
Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's legacy VCD parsing
debian
CVE-2023-39443P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39443 [HIGH] CVE-2023-39443: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functiona...
Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop.
Scope: local
bookworm: resolve
debian
CVE-2023-37445P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37445 [HIGH] CVE-2023-37445: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utility.
S
debian
CVE-2023-39444P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39444 [HIGH] CVE-2023-39444: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functiona...
Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.
Scope: local
bookworm: resolve
debian
CVE-2023-37446P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37446 [HIGH] CVE-2023-37446: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt2 conversion utility.
debian
CVE-2023-37447P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37447 [HIGH] CVE-2023-37447: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utility.
S
debian
1 / 5Next →