Debian Gtkwave vulnerabilities
82 known vulnerabilities affecting debian/gtkwave.
Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82
Vulnerabilities
Page 2 of 5
CVE-2023-37573P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37573 [HIGH] CVE-2023-37573: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu...
Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the GUI's recoder (default) VCD parsing code
debian
CVE-2023-36747P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36747 [HIGH] CVE-2023-36747: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl...
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the handling of `len` in `fstWritex` when `beg_time` does not match
debian
CVE-2023-35703P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35703 [HIGH] CVE-2023-35703: gtkwave - Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 var...
Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint64 function.
Scope: local
bookworm: resolved (fixed in 3.
debian
CVE-2023-35704P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35704 [HIGH] CVE-2023-35704: gtkwave - Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 var...
Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32WithSkip function.
Scope: local
bookworm: resolved (fix
debian
CVE-2023-36915P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36915 [HIGH] CVE-2023-36915: gtkwave - Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 ...
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table` array.
Scope: local
b
debian
CVE-2023-35970P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35970 [HIGH] CVE-2023-35970: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl...
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of the `FST_BL_VCDATA_DYN_ALIAS2` sect
debian
CVE-2023-37442P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37442 [HIGH] CVE-2023-37442: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's default VCD parsing code
debian
CVE-2023-37444P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37444 [HIGH] CVE-2023-37444: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's interactive VCD parsing
debian
CVE-2023-37922P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37922 [HIGH] CVE-2023-37922: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio...
Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt2 conversion utility.
Scope: local
bo
debian
CVE-2023-37443P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37443 [HIGH] CVE-2023-37443: gtkwave - Multiple out-of-bounds read vulnerabilities exist in the VCD var definition sect...
Multiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds read when triggered via the GUI's legacy VCD parsing code.
debian
CVE-2023-37921P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37921 [HIGH] CVE-2023-37921: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio...
Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2vzt conversion utility.
Scope: local
boo
debian
CVE-2023-36916P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36916 [HIGH] CVE-2023-36916: gtkwave - Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 ...
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the allocation of the `chain_table_lengths` array.
Scope:
debian
CVE-2023-37923P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37923 [HIGH] CVE-2023-37923: gtkwave - Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functio...
Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt conversion utility.
Scope: local
boo
debian
CVE-2023-35994P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35994 [HIGH] CVE-2023-35994: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI...
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta initialization part.
Scope: local
bookworm: resolve
debian
CVE-2023-35969P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35969 [HIGH] CVE-2023-35969: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl...
Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of `FST_BL_VCDATA` and `FST_BL_VCDATA_
debian
CVE-2023-35996P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35996 [HIGH] CVE-2023-35996: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI...
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 0.
Scope: local
bookwo
debian
CVE-2023-35995P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35995 [HIGH] CVE-2023-35995: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI...
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 1.
Scope: local
bookwo
debian
CVE-2023-35997P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35997 [HIGH] CVE-2023-35997: gtkwave - Multiple improper array index validation vulnerabilities exist in the fstReaderI...
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the tdelta indexing when signal_lens is 2 or more.
Scope: loca
debian
CVE-2023-37577P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37577 [HIGH] CVE-2023-37577: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu...
Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2lxt2 conversion utility.
Scope: loca
debian
CVE-2023-37576P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37576 [HIGH] CVE-2023-37576: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu...
Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2vzt conversion utility.
Scope: local
debian