Gnu Libredwg vulnerabilities
82 known vulnerabilities affecting gnu/libredwg.
Total CVEs
82
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH56MEDIUM21
Vulnerabilities
Page 2 of 5
CVE-2021-39527HIGHCVSS 8.8≤ 0.10.1.37512021-09-20
CVE-2021-39527 [HIGH] CWE-787 CVE-2021-39527: An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-b
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
nvd
CVE-2021-39521MEDIUMCVSS 6.5≤ 0.10.1.37512021-09-20
CVE-2021-39521 [MEDIUM] CWE-476 CVE-2021-39521: An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the f
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.
nvd
CVE-2021-39523MEDIUMCVSS 6.5≤ 0.10.1.37512021-09-20
CVE-2021-39523 [MEDIUM] CWE-476 CVE-2021-39523: An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the f
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.
nvd
CVE-2021-36080HIGHCVSS 8.8≥ 0.12.3.4163, ≤ 0.12.3.41912021-07-01
CVE-2021-36080 [HIGH] CWE-415 CVE-2021-36080: GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_en
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
nvd
CVE-2020-23861MEDIUMCVSS 5.5v0.10.12021-05-18
CVE-2020-23861 [MEDIUM] CWE-787 CVE-2020-23861: A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page functi
A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.
nvd
CVE-2020-21836HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21836 [HIGH] CWE-787 CVE-2020-21836: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.
nvd
CVE-2020-21813HIGHCVSS 7.8v0.10.26412021-05-17
CVE-2020-21813 [HIGH] CWE-787 CVE-2020-21813: A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/d
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
nvd
CVE-2020-21827HIGHCVSS 7.8v0.102021-05-17
CVE-2020-21827 [HIGH] CWE-787 CVE-2020-21827: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_sect
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.
nvd
CVE-2020-21814HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21814 [HIGH] CWE-787 CVE-2020-21814: A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/e
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
nvd
CVE-2020-21838HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21838 [HIGH] CWE-787 CVE-2020-21838: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.
nvd
CVE-2020-21843HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21843 [HIGH] CWE-787 CVE-2020-21843: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.
nvd
CVE-2020-21830HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21830 [HIGH] CWE-787 CVE-2020-21830: A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/b
A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
nvd
CVE-2020-21818HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21818 [HIGH] CWE-787 CVE-2020-21818: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../pro
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
nvd
CVE-2020-21833HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21833 [HIGH] CWE-787 CVE-2020-21833: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.
nvd
CVE-2020-21832HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21832 [HIGH] CWE-787 CVE-2020-21832: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_sect
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.
nvd
CVE-2020-21840HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21840 [HIGH] CWE-787 CVE-2020-21840: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.
nvd
CVE-2020-21844HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21844 [HIGH] CVE-2020-21844: GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remot
GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580.
nvd
CVE-2020-21841HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21841 [HIGH] CWE-787 CVE-2020-21841: A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.
nvd
CVE-2020-21831HIGHCVSS 8.8v0.102021-05-17
CVE-2020-21831 [HIGH] CWE-787 CVE-2020-21831: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.
nvd
CVE-2020-21819HIGHCVSS 8.8v0.10.26412021-05-17
CVE-2020-21819 [HIGH] CWE-787 CVE-2020-21819: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../prog
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51.
nvd