Gnu Libredwg vulnerabilities
94 known vulnerabilities affecting gnu/libredwg.
Total CVEs
94
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH57MEDIUM26LOW6
Vulnerabilities
Page 3 of 5
CVE-2019-9779P3HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9779 [HIGH] CVE-2019-9779: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
nvd
CVE-2020-21827P3HIGHCVSS 7.8v0.102021-05-17
CVE-2020-21827 [HIGH] CWE-787 CVE-2020-21827: A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_sect
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.
nvd
CVE-2022-33034P3HIGHCVSS 7.8v0.12.4.46082022-06-23
CVE-2022-33034 [HIGH] CWE-787 CVE-2022-33034: LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at deco
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
nvd
CVE-2020-6614P3HIGHCVSS 8.1v0.9.3.25642020-01-08
CVE-2020-6614 [HIGH] CWE-125 CVE-2020-6614: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
nvd
CVE-2020-6612P3HIGHCVSS 8.1v0.9.3.25642020-01-08
CVE-2020-6612 [HIGH] CWE-125 CVE-2020-6612: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
nvd
CVE-2020-6613P3HIGHCVSS 8.1v0.9.3.25642020-01-08
CVE-2020-6613 [HIGH] CWE-125 CVE-2020-6613: GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
nvd
CVE-2019-20910P3HIGHCVSS 8.1≤ 0.9.32020-07-16
CVE-2019-20910 [HIGH] CVE-2019-20910: An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffe
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
nvd
CVE-2022-33024P3HIGHCVSS 7.5v0.12.4.46082022-06-23
CVE-2022-33024 [HIGH] CWE-617 CVE-2022-33024: There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL,
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
nvd
CVE-2023-26157P3HIGHCVSS 7.5fixed in 0.12.5.63842024-01-02
CVE-2023-26157 [HIGH] CWE-400 CVE-2023-26157: Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.
nvd
CVE-2019-9771P3HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9771 [HIGH] CWE-476 CVE-2019-9771: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
nvd
CVE-2019-9776P4HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9776 [HIGH] CWE-476 CVE-2019-9776: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
nvd
CVE-2019-9772P3HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9772 [HIGH] CWE-476 CVE-2019-9772: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
nvd
CVE-2019-20909P4HIGHCVSS 7.5≤ 0.9.32020-07-16
CVE-2019-20909 [HIGH] CWE-476 CVE-2019-20909: An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the fu
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
nvd
CVE-2020-21813P4HIGHCVSS 7.8v0.10.26412021-05-17
CVE-2020-21813 [HIGH] CWE-787 CVE-2020-21813: A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/d
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
nvd
CVE-2021-28236P4HIGHCVSS 7.5v0.12.32021-12-02
CVE-2021-28236 [HIGH] CWE-476 CVE-2021-28236: LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
nvd
CVE-2019-20011P4HIGHCVSS 8.8v0.9.22019-12-27
CVE-2019-20011 [HIGH] CWE-125 CVE-2019-20011: An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
nvd
CVE-2019-20913P4HIGHCVSS 8.1≤ 0.9.32020-07-16
CVE-2019-20913 [HIGH] CWE-125 CVE-2019-20913: An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffe
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
nvd
CVE-2019-20915P4HIGHCVSS 8.1≤ 0.9.32020-07-16
CVE-2019-20915 [HIGH] CWE-125 CVE-2019-20915: An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffe
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
nvd
CVE-2022-33033P4HIGHCVSS 7.8v0.12.4.46082022-06-23
CVE-2022-33033 [HIGH] CWE-415 CVE-2022-33033: LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
nvd
CVE-2019-9777P4HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9777 [HIGH] CWE-125 CVE-2019-9777: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
nvd