cbcvebase.

Debian Gtkwave vulnerabilities

82 known vulnerabilities affecting debian/gtkwave.

Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH82

Vulnerabilities

Page 4 of 5
CVE-2023-39273P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39273 [HIGH] CVE-2023-39273: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `flags` array. Scope: local bookworm:
debian
CVE-2023-39275P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39275 [HIGH] CVE-2023-39275: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `value` array. Scope: local bookworm:
debian
CVE-2023-39271P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39271 [HIGH] CVE-2023-39271: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `msb` array. Scope: local bookworm: re
debian
CVE-2023-39270P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39270 [HIGH] CVE-2023-39270: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing ... Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `rows` array. Scope: local bookworm: r
debian
CVE-2023-39316P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39316 [HIGH] CVE-2023-39316: gtkwave - Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries fun... Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `string_pointers` array. Scope: local boo
debian
CVE-2023-34087P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-34087 [HIGH] CVE-2023-34087: gtkwave - An improper array index validation vulnerability exists in the EVCD var len pars... An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+reall
debian
CVE-2023-38650P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38650 [HIGH] CVE-2023-38650: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_deco... Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when num_time_ticks is not zero. Scope: local boo
debian
CVE-2023-38651P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38651 [HIGH] CVE-2023-38651: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_deco... Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when num_time_ticks is zero. Scope: local bookwor
debian
CVE-2023-38653P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38653 [HIGH] CVE-2023-38653: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_deco... Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when num_time_ticks is zero. Scope: local bookworm
debian
CVE-2023-38652P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38652 [HIGH] CVE-2023-38652: gtkwave - Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_deco... Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when num_time_ticks is not zero. Scope: local book
debian
CVE-2023-36861P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36861 [HIGH] CVE-2023-36861: gtkwave - An out-of-bounds write vulnerability exists in the VZT LZMA_read_varint function... An out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.3.118-0+de
debian
CVE-2023-37282P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-37282 [HIGH] CVE-2023-37282: gtkwave - An out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction... An out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.3
debian
CVE-2023-38583P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38583 [HIGH] CVE-2023-38583: gtkwave - A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_in... A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+
debian
CVE-2023-38657P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-38657 [HIGH] CVE-2023-38657: gtkwave - An out-of-bounds write vulnerability exists in the LXT2 zlib block decompression... An out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.
debian
CVE-2023-35989P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35989 [HIGH] CVE-2023-35989: gtkwave - An integer overflow vulnerability exists in the LXT2 zlib block allocation funct... An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.3.118-
debian
CVE-2023-34436P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-34436 [HIGH] CVE-2023-34436: gtkwave - An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries f... An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+really3.3.
debian
CVE-2023-36864P3HIGHCVSS 7.8fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-36864 [HIGH] CVE-2023-36864: gtkwave - An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal... An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed
debian
CVE-2023-32650P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-32650 [HIGH] CVE-2023-32650: gtkwave - An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle fu... An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fi
debian
CVE-2023-35128P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-35128 [HIGH] CVE-2023-35128: gtkwave - An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table ... An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 3.3.118-0.1~deb12u1) bullseye: resolved (fixed in 3.3.104+reall
debian
CVE-2023-39414P3HIGHCVSS 7.0fixed in gtkwave 3.3.118-0.1~deb12u1 (bookworm)2023
CVE-2023-39414 [HIGH] CVE-2023-39414: gtkwave - Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix ... Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer underflow when performing the right shift operation. Scope
debian