cbcvebase.

Debian Gtkwave vulnerabilities

82 known vulnerabilities affecting debian/gtkwave.

Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82

Vulnerabilities

Page 3 of 5
CVE-2023-37578P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37578 [HIGH] CVE-2023-37578: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the vcd2lxt conversion utility. Scope: local
debian
CVE-2023-37575P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37575 [HIGH] CVE-2023-37575: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the GUI's interactive VCD parsing code. Scop
debian
CVE-2023-37574P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37574 [HIGH] CVE-2023-37574: gtkwave - Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc fu... Multiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the use-after-free when triggered via the GUI's legacy VCD parsing code. Scope: lo
debian
CVE-2023-39413P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39413 [HIGH] CVE-2023-39413: gtkwave - Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix ... Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the left shift operation. Scope:
debian
CVE-2023-36746P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36746 [HIGH] CVE-2023-36746: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the handling of `len` in `fstWritex` when parsing the time table. S
debian
CVE-2023-35956P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35956 [HIGH] CVE-2023-35956: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `fastlz_decompress`. Scope: loca
debian
CVE-2023-35958P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35958 [HIGH] CVE-2023-35958: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the copy function `fstFread`. Scope: local bookworm: resolv
debian
CVE-2023-35702P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35702 [HIGH] CVE-2023-35702: gtkwave - Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 var... Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32 function. Scope: local bookworm: resolved (fixed in 3.
debian
CVE-2023-35955P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35955 [HIGH] CVE-2023-35955: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `LZ4_decompress_safe_partial`. S
debian
CVE-2023-38619P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38619 [HIGH] CVE-2023-38619: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `msb` array. Scope: local bookworm: reso
debian
CVE-2023-38618P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38618 [HIGH] CVE-2023-38618: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `rows` array. Scope: local bookworm: res
debian
CVE-2023-38622P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38622 [HIGH] CVE-2023-38622: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `len` array. Scope: local bookworm: reso
debian
CVE-2023-35004P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35004 [HIGH] CVE-2023-35004: gtkwave - An integer overflow vulnerability exists in the VZT longest_len value allocation... An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.3
debian
CVE-2023-38620P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38620 [HIGH] CVE-2023-38620: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `lsb` array. Scope: local bookworm: reso
debian
CVE-2023-38623P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38623 [HIGH] CVE-2023-38623: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `vindex_offset` array. Scope: local book
debian
CVE-2023-38621P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38621 [HIGH] CVE-2023-38621: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing f... Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `flags` array. Scope: local bookworm: re
debian
CVE-2023-39274P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39274 [HIGH] CVE-2023-39274: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `len` array. Scope: local bookworm: re
debian
CVE-2023-39317P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39317 [HIGH] CVE-2023-39317: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries fun... Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `string_lens` array. Scope: local bookwor
debian
CVE-2023-35957P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35957 [HIGH] CVE-2023-35957: gtkwave - Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBl... Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `uncompress`. Scope: local bookw
debian
CVE-2023-39272P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39272 [HIGH] CVE-2023-39272: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `lsb` array. Scope: local bookworm: re
debian
Debian Gtkwave vulnerabilities | cvebase