cbcvebase.

Gnu Libredwg vulnerabilities

94 known vulnerabilities affecting gnu/libredwg.

Total CVEs
94
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH57MEDIUM26LOW6

Vulnerabilities

Page 5 of 5
CVE-2018-14471P4MEDIUMCVSS 6.5fixed in 0.62018-07-20
CVE-2018-14471 [MEDIUM] CWE-476 CVE-2018-14471: dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attacker dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
nvd
CVE-2019-20911P4MEDIUMCVSS 6.5≤ 0.9.32020-07-16
CVE-2019-20911 [MEDIUM] CWE-835 CVE-2019-20911: An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
nvd
CVE-2018-14524P4MEDIUMCVSS 6.5fixed in 0.62018-07-23
CVE-2018-14524 [MEDIUM] CWE-415 CVE-2018-14524: dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in fre dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.
nvd
CVE-2021-39521P4MEDIUMCVSS 6.5≤ 0.10.1.37512021-09-20
CVE-2021-39521 [MEDIUM] CWE-476 CVE-2021-39521: An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the f An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.
nvd
CVE-2021-39523P4MEDIUMCVSS 6.5≤ 0.10.1.37512021-09-20
CVE-2021-39523 [MEDIUM] CWE-476 CVE-2021-39523: An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the f An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.
nvd
CVE-2020-21817P4MEDIUMCVSS 6.5v0.10.26412021-05-17
CVE-2020-21817 [MEDIUM] CWE-476 CVE-2020-21817: A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/esca A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).
nvd
CVE-2020-21815P4MEDIUMCVSS 6.5v0.10.26412021-05-17
CVE-2020-21815 [MEDIUM] CWE-476 CVE-2020-21815: A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2S A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).
nvd
CVE-2020-23861P4MEDIUMCVSS 5.5v0.10.12021-05-18
CVE-2020-23861 [MEDIUM] CWE-787 CVE-2020-23861: A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page functi A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.
nvd
CVE-2026-9504P4LOWCVSS 3.3v0.1v0.2+12 more2026-05-25
CVE-2026-9504 [LOW] CWE-119 CVE-2026-9504: A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU o A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility. This manipulation causes out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: be996bf2178a4
cvelistv5nvd
CVE-2026-9501P4LOWCVSS 3.3v0.1v0.2+12 more2026-05-25
CVE-2026-9501 [LOW] CWE-617 CVE-2026-9501: A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function deco A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. This patch i
cvelistv5nvd
CVE-2026-9530P4LOWCVSS 3.3v0.1v0.2+12 more2026-05-26
CVE-2026-9530 [LOW] CWE-119 CVE-2026-9530: A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a manipulation can lead to out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. T
nvd
CVE-2026-15184P4LOWCVSS 3.3v0.13.0v0.13.1+3 more2026-07-09
CVE-2026-15184 [LOW] CWE-404 CVE-2026-15184: A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_nex A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a manipulation of the argument next_obj results in null pointer dereference. The attack must be initiated from a local position. The exploit has been made public and could be us
nvd
CVE-2026-9503P4LOWCVSS 3.3v0.1v0.2+12 more2026-05-25
CVE-2026-9503 [LOW] CWE-404 CVE-2026-9503: A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_e A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The patch i
cvelistv5nvd
CVE-2026-9529P4LOWCVSS 3.3v0.1v0.2+12 more2026-05-26
CVE-2026-9529 [LOW] CWE-404 CVE-2026-9529: A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulation results in null pointer dereference. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.
nvd
Gnu Libredwg vulnerabilities | cvebase