Gerbv Project Gerbv vulnerabilities
8 known vulnerabilities affecting gerbv_project/gerbv.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-4508MEDIUMCVSS 5.5≥ 2.4.0, ≤ 2.10.02023-08-24
CVE-2023-4508 [MEDIUM] CWE-824 CVE-2023-4508: A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
nvdosv
CVE-2021-40402HIGHCVSS 7.5v2.7.0v2.7.1+1 more2022-04-14
CVE-2021-40402 [HIGH] CWE-755 CVE-2021-40402: An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives
An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2021-40400HIGHCVSS 7.5v2.7.02022-04-14
CVE-2021-40400 [HIGH] CWE-119 CVE-2021-40400: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functiona
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2021-40401HIGHCVSS 8.6v2.7.0v2.7.1+1 more2022-02-04
CVE-2021-40401 [HIGH] CWE-252 CVE-2021-40401: A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2021-40403MEDIUMCVSS 6.3v2.7.0v2.8.0+1 more2022-02-04
CVE-2021-40403 [MEDIUM] CWE-456 CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerabil
nvdosv
CVE-2021-40394CRITICALCVSS 9.8v2.7.0vGerbv 2.7.0,Gerbv dev (commit b5f1eacd), Gerbv forked dev (commit 71493260)2021-12-22
CVE-2021-40394 [CRITICAL] CWE-787 CVE-2021-40394: An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functio
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2021-40393CRITICALCVSS 9.8v2.7.0vGerbv 2.7.0, Gerbv dev (commit b5f1eacd),Gerbv forked dev (commit 71493260)2021-12-22
CVE-2021-40393 [CRITICAL] CWE-119 CVE-2021-40393: An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functio
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv
CVE-2021-40391CRITICALCVSS 9.8v2.7.0vGerbv 2.7.0 , Gerbv dev (commit b5f1eacd) ,Gerbv forked dev (commit 71493260)2021-11-19
CVE-2021-40391 [CRITICAL] CWE-390 CVE-2021-40391: An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvdosv