Msrc Azl3 Graphviz 2.42.4-12 On Azure Linux 3.0 vulnerabilities
2 known vulnerabilities affecting msrc/azl3_graphviz_2.42.4-12_on_azure_linux_3.0.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2023-46045HIGHCVSS 7.82024-02-13
CVE-2023-46045 [HIGH] CWE-125 Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potent
msrc
CVE-2020-18032HIGHCVSS 7.82021-04-13
CVE-2020-18032 [HIGH] CWE-120 Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
FAQ: Is Azu
msrc