Gnu Libredwg vulnerabilities
94 known vulnerabilities affecting gnu/libredwg.
Total CVEs
94
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH57MEDIUM26LOW6
Vulnerabilities
Page 2 of 5
CVE-2023-25222P3HIGHCVSS 8.8v0.12.52023-03-01
CVE-2023-25222 [HIGH] CWE-787 CVE-2023-25222: A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC functio
A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.
nvd
CVE-2023-36273P3HIGHCVSS 8.8v0.12.52023-06-23
CVE-2023-36273 [HIGH] CWE-787 CVE-2023-36273: LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at b
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
nvd
CVE-2022-35164P3CRITICALCVSS 9.8fixed in 0.12.4.46082022-08-18
CVE-2022-35164 [CRITICAL] CWE-416 CVE-2022-35164: LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
nvd
CVE-2019-20010P3HIGHCVSS 8.8v0.9.22019-12-27
CVE-2019-20010 [HIGH] CWE-416 CVE-2019-20010: An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
nvd
CVE-2020-21830P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21830 [HIGH] CWE-787 CVE-2020-21830: A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/b
A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
nvd
CVE-2019-20914P3CRITICALCVSS 9.8≤ 0.9.32020-07-16
CVE-2019-20914 [CRITICAL] CWE-476 CVE-2019-20914: An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the fu
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
nvd
CVE-2020-6609P3HIGHCVSS 8.8v0.9.3.25642020-01-08
CVE-2020-6609 [HIGH] CWE-125 CVE-2020-6609: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
nvd
CVE-2019-20014P3HIGHCVSS 8.8fixed in 0.9.32019-12-27
CVE-2019-20014 [HIGH] CWE-415 CVE-2019-20014: An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
nvd
CVE-2020-21843P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21843 [HIGH] CWE-787 CVE-2020-21843: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.
nvd
CVE-2020-21833P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21833 [HIGH] CWE-787 CVE-2020-21833: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.
nvd
CVE-2021-39528P3HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39528 [HIGH] CWE-415 CVE-2021-39528: An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec ha
An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
nvd
CVE-2021-39530P3HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39530 [HIGH] CWE-787 CVE-2021-39530: An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.
nvd
CVE-2021-39522P3HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39522 [HIGH] CWE-787 CVE-2021-39522: An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based b
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.
nvd
CVE-2021-39525P3HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39525 [HIGH] CWE-787 CVE-2021-39525: An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-base
An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.
nvd
CVE-2021-39527P3HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39527 [HIGH] CWE-787 CVE-2021-39527: An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-b
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
nvd
CVE-2020-21838P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21838 [HIGH] CWE-787 CVE-2020-21838: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.
nvd
CVE-2020-21840P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21840 [HIGH] CWE-787 CVE-2020-21840: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.
nvd
CVE-2020-21841P3HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21841 [HIGH] CWE-787 CVE-2020-21841: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.
nvd
CVE-2019-9770P3HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9770 [HIGH] CWE-787 CVE-2019-9770: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
nvd
CVE-2019-9773P3HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9773 [HIGH] CWE-787 CVE-2019-9773: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in t
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
nvd