CVE-2025-15523
- EPSS 0.01%
- Veröffentlicht 22.01.2026 14:45:26
- Zuletzt bearbeitet 26.01.2026 15:04:33
MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbi...
CVE-2021-42700
- EPSS 0.47%
- Veröffentlicht 18.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:00
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
CVE-2021-42702
- EPSS 0.47%
- Veröffentlicht 18.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:00
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
CVE-2021-42704
- EPSS 1.33%
- Veröffentlicht 18.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:00
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
CVE-2012-6076
- EPSS 0.11%
- Veröffentlicht 12.03.2013 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.
CVE-2012-5656
- EPSS 0.05%
- Veröffentlicht 18.01.2013 11:48:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
CVE-2007-1463
- EPSS 11.26%
- Veröffentlicht 21.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.
CVE-2007-1464
- EPSS 9.16%
- Veröffentlicht 21.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
CVE-2005-3885
- EPSS 0.08%
- Veröffentlicht 29.11.2005 19:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
CVE-2005-3737
- EPSS 28.06%
- Veröffentlicht 22.11.2005 00:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.