Known Vulnerabilities for Libredwg by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Libredwg" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-36274 json | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c. | 8.8 - HIGH | 2023-06-23 | 2023-06-27 |
| CVE-2023-36273 json | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | 8.8 - HIGH | 2023-06-23 | 2023-06-27 |
| CVE-2023-36272 json | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c. | 8.8 - HIGH | 2023-06-23 | 2023-06-27 |
| CVE-2023-36271 json | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c. | 8.8 - HIGH | 2023-06-23 | 2023-06-27 |
| CVE-2023-26157 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2024-01-02 | 2024-01-08 |
| CVE-2023-25222 json | A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c. | 8.8 - HIGH | 2023-03-01 | 2023-03-10 |
| CVE-2022-45332 json | LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r... | 7.8 - HIGH | 2022-11-30 | 2022-12-02 |
| CVE-2022-35164 json | LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. | 9.8 - CRITICAL | 2022-08-18 | 2022-08-19 |
| CVE-2022-33034 json | LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. | 7.8 - HIGH | 2022-06-23 | 2022-06-29 |
| CVE-2022-33033 json | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. | 7.8 - HIGH | 2022-06-23 | 2022-06-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Libredwg | 0.93 | |||
| Application | Gnu | Libredwg | 0.92 | |||
| Application | Gnu | Libredwg | 0.9.3.2628 | |||
| Application | Gnu | Libredwg | 0.9.3.2622 | |||
| Application | Gnu | Libredwg | 0.9.3.2618 | |||
| Application | Gnu | Libredwg | 0.9.3.2613 | |||
| Application | Gnu | Libredwg | 0.9.3.2600 | |||
| Application | Gnu | Libredwg | 0.9.3.2595 | |||
| Application | Gnu | Libredwg | 0.9.3.2582 | |||
| Application | Gnu | Libredwg | 0.9.3.2564 | |||
| Application | Gnu | Libredwg | 0.9.3.2560 | |||
| Application | Gnu | Libredwg | 0.9.3.2543 | |||
| Application | Gnu | Libredwg | 0.9.3.2531 | |||
| Application | Gnu | Libredwg | 0.9.3.2529 | |||
| Application | Gnu | Libredwg | 0.9.3.2523 | |||
| Application | Gnu | Libredwg | 0.9.3.2520 | |||
| Application | Gnu | Libredwg | 0.9.3.2519 | |||
| Application | Gnu | Libredwg | 0.9.3.2495 | |||
| Application | Gnu | Libredwg | 0.9.3.2494 | |||
| Application | Gnu | Libredwg | 0.9.3.2492 |