Gnu

Libredwg

100 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.02%
  • Veröffentlicht 16.07.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:39:40

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.

Exploit
  • EPSS 1.25%
  • Veröffentlicht 16.07.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:39:40

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.

Exploit
  • EPSS 1.62%
  • Veröffentlicht 16.07.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:39:39

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

Exploit
  • EPSS 1.67%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:02

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.

Exploit
  • EPSS 1.76%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:01

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

Exploit
  • EPSS 1.37%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:01

GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

Exploit
  • EPSS 1.53%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:01

GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.

Exploit
  • EPSS 1.67%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:01

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

Exploit
  • EPSS 1.51%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:02

GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

Exploit
  • EPSS 1.67%
  • Veröffentlicht 08.01.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:01

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.