cbcvebase.

Gnu Libredwg vulnerabilities

94 known vulnerabilities affecting gnu/libredwg.

Total CVEs
94
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH57MEDIUM26LOW6

Vulnerabilities

Page 4 of 5
CVE-2019-9778P4HIGHCVSS 7.5v0.7v0.7.16452019-03-14
CVE-2019-9778 [HIGH] CWE-125 CVE-2019-9778: An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
nvd
CVE-2022-45332P4HIGHCVSS 7.8v0.12.4.46432022-11-30
CVE-2022-45332 [HIGH] CWE-787 CVE-2022-45332: LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR1 LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.
nvd
CVE-2026-15182P4MEDIUMCVSS 5.3v0.13.0v0.13.1+3 more2026-07-09
CVE-2026-15182 [MEDIUM] CWE-119 CVE-2026-15182: A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dw A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component BMP Image Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 0.14 is s
nvd
CVE-2025-61154P4MEDIUMCVSS 6.5≥ 0.13.3.7571, ≤ 0.13.3.78352026-03-12
CVE-2025-61154 [MEDIUM] CWE-122 CVE-2025-61154: Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a cra Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.
nvd
CVE-2026-15520P4MEDIUMCVSS 5.3v0.13.4-154-g0b5730352026-07-13
CVE-2026-15520 [MEDIUM] CWE-119 CVE-2026-15520: A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decom A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-9500P4MEDIUMCVSS 5.3v0.1v0.2+12 more2026-05-25
CVE-2026-9500 [MEDIUM] CWE-119 CVE-2026-9500: A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004 A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been made public and could be used. The projec
cvelistv5nvd
CVE-2021-45950P4MEDIUMCVSS 6.5≥ 0.12.4.4313, ≤ 0.12.4.43672022-01-01
CVE-2021-45950 [MEDIUM] CWE-787 CVE-2021-45950: LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (calle LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).
nvd
CVE-2026-9502P4MEDIUMCVSS 5.3v0.1v0.2+12 more2026-05-25
CVE-2026-9502 [MEDIUM] CWE-119 CVE-2026-9502: A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R200 A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is e501cb
cvelistv5nvd
CVE-2020-15807P4MEDIUMCVSS 6.5fixed in 0.112020-07-17
CVE-2020-15807 [MEDIUM] CWE-476 CVE-2020-15807: GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
nvd
CVE-2019-20013P4MEDIUMCVSS 6.5fixed in 0.9.32019-12-27
CVE-2019-20013 [MEDIUM] CWE-770 CVE-2019-20013: An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessi An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
nvd
CVE-2019-20009P4MEDIUMCVSS 6.5fixed in 0.9.32019-12-27
CVE-2019-20009 [MEDIUM] CWE-770 CVE-2019-20009: An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessi An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
nvd
CVE-2019-20015P4MEDIUMCVSS 6.5v0.9.22019-12-27
CVE-2019-20015 [MEDIUM] CWE-770 CVE-2019-20015: An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memo An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
nvd
CVE-2019-20012P4MEDIUMCVSS 6.5v0.9.22019-12-27
CVE-2019-20012 [MEDIUM] CWE-770 CVE-2019-20012: An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memo An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
nvd
CVE-2018-14443P4MEDIUMCVSS 6.5fixed in 0.62018-07-20
CVE-2018-14443 [MEDIUM] CWE-119 CVE-2018-14443: get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial o get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
nvd
CVE-2020-21835P4MEDIUMCVSS 6.5v0.102021-05-17
CVE-2020-21835 [MEDIUM] CWE-476 CVE-2020-21835: A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../sr A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.
nvd
CVE-2020-6610P4MEDIUMCVSS 6.5v0.9.3.25642020-01-08
CVE-2020-6610 [MEDIUM] CWE-770 CVE-2020-6610: GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_ GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
nvd
CVE-2020-21839P4MEDIUMCVSS 6.5v0.102021-05-17
CVE-2020-21839 [MEDIUM] CWE-401 CVE-2020-21839: An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decod An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.
nvd
CVE-2020-21834P4MEDIUMCVSS 6.5v0.102021-05-17
CVE-2020-21834 [MEDIUM] CWE-476 CVE-2020-21834: A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164. A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.
nvd
CVE-2020-6611P4MEDIUMCVSS 6.5v0.9.3.25642020-01-08
CVE-2020-6611 [MEDIUM] CWE-476 CVE-2020-6611: GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
nvd
CVE-2020-6615P4MEDIUMCVSS 6.5v0.9.3.25642020-01-08
CVE-2020-6615 [MEDIUM] CWE-476 CVE-2020-6615: GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (d GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
nvd
Gnu Libredwg vulnerabilities | cvebase