cbcvebase.

Debian Gtkwave vulnerabilities

82 known vulnerabilities affecting debian/gtkwave.

Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82

Vulnerabilities

Page 2 of 5
CVE-2023-37573P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37573 [HIGH] CVE-2023-37573: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the GUI's recoder (default) VCD parsing code
debian
CVE-2023-36747P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36747 [HIGH] CVE-2023-36747: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the handling of `len` in `fstWritex` when `beg_time` does not match
debian
CVE-2023-35703P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35703 [HIGH] CVE-2023-35703: gtkwave - Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 var... Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint64 function. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2023-35704P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35704 [HIGH] CVE-2023-35704: gtkwave - Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 var... Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32WithSkip function. Scope: local bookworm: resolved (fix
debian
CVE-2023-36915P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36915 [HIGH] CVE-2023-36915: gtkwave - Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 ... Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table` array. Scope: local b
debian
CVE-2023-35970P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35970 [HIGH] CVE-2023-35970: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of the `FST_BL_VCDATA_DYN_ALIAS2` sect
debian
CVE-2023-37442P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37442 [HIGH] CVE-2023-37442: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's default VCD parsing code
debian
CVE-2023-37444P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37444 [HIGH] CVE-2023-37444: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's interactive VCD parsing
debian
CVE-2023-37922P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37922 [HIGH] CVE-2023-37922: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio... Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt2 conversion utility. Scope: local bo
debian
CVE-2023-37443P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37443 [HIGH] CVE-2023-37443: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect... Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's legacy VCD parsing code.
debian
CVE-2023-37921P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37921 [HIGH] CVE-2023-37921: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio... Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2vzt conversion utility. Scope: local boo
debian
CVE-2023-36916P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36916 [HIGH] CVE-2023-36916: gtkwave - Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 ... Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table_lengths` array. Scope:
debian
CVE-2023-37923P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37923 [HIGH] CVE-2023-37923: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio... Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt conversion utility. Scope: local boo
debian
CVE-2023-35994P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35994 [HIGH] CVE-2023-35994: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI... Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta initialization part. Scope: local bookworm: resolve
debian
CVE-2023-35969P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35969 [HIGH] CVE-2023-35969: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of `FST_BL_VCDATA` and `FST_BL_VCDATA_
debian
CVE-2023-35996P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35996 [HIGH] CVE-2023-35996: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI... Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 0. Scope: local bookwo
debian
CVE-2023-35995P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35995 [HIGH] CVE-2023-35995: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI... Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 1. Scope: local bookwo
debian
CVE-2023-35997P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35997 [HIGH] CVE-2023-35997: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI... Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 2 or more. Scope: loca
debian
CVE-2023-37577P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37577 [HIGH] CVE-2023-37577: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2lxt2 conversion utility. Scope: loca
debian
CVE-2023-37576P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37576 [HIGH] CVE-2023-37576: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2vzt conversion utility. Scope: local
debian
Debian Gtkwave vulnerabilities | cvebase