Fig2Dev Project Fig2Dev vulnerabilities
32 known vulnerabilities affecting fig2dev_project/fig2dev.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM28
Vulnerabilities
Page 2 of 2
CVE-2020-21682MEDIUMCVSS 5.5v3.2.7b2021-08-10
CVE-2020-21682 [MEDIUM] CWE-120 CVE-2020-21682: A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to
A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
nvdosv
CVE-2020-21675MEDIUMCVSS 5.5v3.2.7b2021-08-10
CVE-2020-21675 [MEDIUM] CWE-787 CVE-2020-21675: A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows atta
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
nvdosv
CVE-2020-21684MEDIUMCVSS 5.5v3.2.7b2021-08-10
CVE-2020-21684 [MEDIUM] CWE-120 CVE-2020-21684: A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
nvdosv
CVE-2020-21676MEDIUMCVSS 5.5v3.2.7b2021-08-10
CVE-2020-21676 [MEDIUM] CWE-787 CVE-2020-21676: A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b al
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
nvdosv
CVE-2020-21683MEDIUMCVSS 5.5v3.2.7b2021-08-10
CVE-2020-21683 [MEDIUM] CWE-120 CVE-2020-21683: A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
nvdosv
CVE-2021-3561HIGHCVSS 7.1v3.2.8vfig2dev 3.2.8a2021-05-26
CVE-2021-3561 [HIGH] CWE-119 CVE-2021-3561: An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() coul
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
cvelistv5nvdosv
CVE-2019-19797MEDIUMCVSS 5.5≥ 0, < 1:3.2.7b-32019-12-15
CVE-2019-19797 [MEDIUM] CVE-2019-19797: read_colordef in read
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
osv
CVE-2019-19746MEDIUMCVSS 5.5v3.2.7b2019-12-12
CVE-2019-19746 [MEDIUM] CWE-190 CVE-2019-19746: make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write bec
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
nvdosv
CVE-2019-19555MEDIUMCVSS 5.5≥ 0, < 1:3.2.7b-22019-12-04
CVE-2019-19555 [MEDIUM] CVE-2019-19555: read_textobject in read
read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
osv
CVE-2019-14275MEDIUMCVSS 5.5≥ 0, < 1:3.2.7a-72019-07-26
CVE-2019-14275 [MEDIUM] CVE-2019-14275: Xfig fig2dev 3
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
osv
CVE-2018-16140HIGHCVSS 7.8v3.2.7a2018-08-30
CVE-2018-16140 [HIGH] CWE-787 CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to wri
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
nvdosv
CVE-2017-16899HIGHCVSS 7.1≥ 0, < 1:3.2.6a-52017-11-20
CVE-2017-16899 [HIGH] CVE-2017-16899: An array index error in the fig2dev program in Xfig 3
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.
osv
← Previous2 / 2