CVE-2026-77652
- EPSS 0.15%
- Veröffentlicht 26.08.2026 19:21:39
- Zuletzt bearbeitet 28.08.2026 15:44:39
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a W...
CVE-2026-77658
- EPSS 0.14%
- Veröffentlicht 26.08.2026 12:10:07
- Zuletzt bearbeitet 28.08.2026 15:44:39
A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" u...
CVE-2019-19451
- EPSS 0.37%
- Veröffentlicht 29.11.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:45
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output w...