cbcvebase.

Debian Gtkwave vulnerabilities

82 known vulnerabilities affecting debian/gtkwave.

Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82

Vulnerabilities

Page 1 of 5
CVE-2023-35961P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35961 [HIGH] CVE-2023-35961: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in `vcd_recorder_main`. Scope: local bookworm: resolved (fixed in 3.3.
debian
CVE-2023-35959P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35959 [HIGH] CVE-2023-35959: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns `.ghw` decompression. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1)
debian
CVE-2023-35963P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35963 [HIGH] CVE-2023-35963: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt2` utility. Scope: local bookworm: resolved (fixed in 3
debian
CVE-2023-35962P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35962 [HIGH] CVE-2023-35962: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2vzt` utility. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2023-35964P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35964 [HIGH] CVE-2023-35964: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in the `vcd2lxt` utility. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2023-35960P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35960 [HIGH] CVE-2023-35960: gtkwave - Multiple OS command injection vulnerabilities exist in the decompression functio... Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns legacy decompression in `vcd_main`. Scope: local bookworm: resolved (fixed in 3.3.11
debian
CVE-2023-39234P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39234 [HIGH] CVE-2023-39234: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_blo... Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when looping over `lt->numrealfacs`. Scope:
debian
CVE-2023-37419P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37419 [HIGH] CVE-2023-37419: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ... Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt2 conversion util
debian
CVE-2023-37420P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37420 [HIGH] CVE-2023-37420: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ... Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utili
debian
CVE-2023-38649P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38649 [HIGH] CVE-2023-38649: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname... Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop. Scope:
debian
CVE-2023-38648P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38648 [HIGH] CVE-2023-38648: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname... Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_get_facname decompression functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop. Scope:
debian
CVE-2023-37418P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37418 [HIGH] CVE-2023-37418: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ... Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utili
debian
CVE-2023-39235P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39235 [HIGH] CVE-2023-39235: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_blo... Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when looping over `lt->num_time_ticks`. Scop
debian
CVE-2023-37417P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37417 [HIGH] CVE-2023-37417: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ... Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's interactive VCD pa
debian
CVE-2023-37416P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37416 [HIGH] CVE-2023-37416: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange ... Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's legacy VCD parsing
debian
CVE-2023-39443P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39443 [HIGH] CVE-2023-39443: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functiona... Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the prefix copy loop. Scope: local bookworm: resolve
debian
CVE-2023-37445P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37445 [HIGH] CVE-2023-37445: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utility. S
debian
CVE-2023-39444P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39444 [HIGH] CVE-2023-39444: gtkwave - Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functiona... Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop. Scope: local bookworm: resolve
debian
CVE-2023-37446P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37446 [HIGH] CVE-2023-37446: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt2 conversion utility.
debian
CVE-2023-37447P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37447 [HIGH] CVE-2023-37447: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utility. S
debian
Debian Gtkwave vulnerabilities | cvebase