Gnu Libredwg vulnerabilities
94 known vulnerabilities affecting gnu/libredwg.
Total CVEs
94
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH57MEDIUM26LOW6
Vulnerabilities
Page 1 of 5
CVE-2026-9605P3HIGHCVSS 7.3v0.13.4.81602026-05-27
CVE-2026-9605 [HIGH] CWE-119 CVE-2026-9605: A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC
A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 8f03865f37f5d4ffd616fef802acc980be54d3
nvd
CVE-2020-21844P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21844 [HIGH] CVE-2020-21844: GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remot
GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580.
nvd
CVE-2021-28237P3CRITICALCVSS 9.8v0.12.32021-12-02
CVE-2021-28237 [CRITICAL] CWE-787 CVE-2021-28237: LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
nvd
CVE-2019-9775P3CRITICALCVSS 9.1v0.7v0.7.16452019-03-14
CVE-2019-9775 [CRITICAL] CWE-125 CVE-2019-9775: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the func
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.
nvd
CVE-2019-9774P3CRITICALCVSS 9.1v0.7v0.7.16452019-03-14
CVE-2019-9774 [CRITICAL] CWE-125 CVE-2019-9774: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the func
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
nvd
CVE-2020-21816P3HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21816 [HIGH] CWE-787 CVE-2020-21816: A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/es
A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.
nvd
CVE-2021-36080P3HIGHCVSS 8.8≥ 0.12.3.4163, ≤ 0.12.3.41912021-07-01
CVE-2021-36080 [HIGH] CWE-415 CVE-2021-36080: GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_en
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
nvd
CVE-2019-20912P3HIGHCVSS 8.8≤ 0.9.32020-07-16
CVE-2019-20912 [HIGH] CWE-787 CVE-2019-20912: An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow i
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.
nvd
CVE-2020-21832P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21832 [HIGH] CWE-787 CVE-2020-21832: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_sect
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.
nvd
CVE-2020-21842P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21842 [HIGH] CWE-787 CVE-2020-21842: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhist
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.
nvd
CVE-2020-21818P3HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21818 [HIGH] CWE-787 CVE-2020-21818: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../pro
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
nvd
CVE-2020-21836P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21836 [HIGH] CWE-787 CVE-2020-21836: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.
nvd
CVE-2020-21831P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21831 [HIGH] CWE-787 CVE-2020-21831: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.
nvd
CVE-2020-21819P3HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21819 [HIGH] CWE-787 CVE-2020-21819: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../prog
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.
nvd
CVE-2020-21814P3HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21814 [HIGH] CWE-787 CVE-2020-21814: A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/e
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
nvd
CVE-2021-42586P3HIGHCVSS 8.8fixed in 0.12.42022-05-23
CVE-2021-42586 [HIGH] CWE-787 CVE-2021-42586: A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a
A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
nvd
CVE-2021-42585P3HIGHCVSS 8.8fixed in 0.12.42022-05-23
CVE-2021-42585 [HIGH] CWE-787 CVE-2021-42585: A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0
A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
nvd
CVE-2023-36271P3HIGHCVSS 8.8≥ 0.10, ≤ 0.12.52023-06-23
CVE-2023-36271 [HIGH] CWE-787 CVE-2023-36271: LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
nvd
CVE-2023-36274P3HIGHCVSS 8.8≥ 0.11, ≤ 0.12.52023-06-23
CVE-2023-36274 [HIGH] CWE-787 CVE-2023-36274: LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_writ
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
nvd
CVE-2023-36272P3HIGHCVSS 8.8≥ 0.10, ≤ 0.12.52023-06-23
CVE-2023-36272 [HIGH] CWE-787 CVE-2023-36272: LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
nvd
1 / 5Next →