📦 Libredwg

by Gnu

🔍 What is Libredwg?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-28237

CRITICAL CVSS 9.8 Dec 2, 2021

LibreDWG v0.12.3 contains a heap-buffer overflow vulnerability in the decode_preR13 function that allows attackers to execute arbitrary code or cause denial of service. This affects any application or...

CVE-2023-36272

HIGH CVSS 8.8 Jun 23, 2023

LibreDWG versions 0.10 through 0.12.5 contain a heap buffer overflow vulnerability in the bit_utf8_to_TU function. This allows attackers to execute arbitrary code or cause denial of service by process...

CVE-2023-36274

HIGH CVSS 8.8 Jun 23, 2023

CVE-2023-36274 is a heap buffer overflow vulnerability in LibreDWG's bit_write_TF function that allows attackers to execute arbitrary code or cause denial of service. This affects systems using LibreD...

CVE-2022-33025

HIGH CVSS 7.8 Jun 23, 2022

LibreDWG v0.12.4.4608 contains a heap-use-after-free vulnerability in the decode_preR13_section function at decode_r11.c. This allows attackers to potentially execute arbitrary code or cause denial of...

CVE-2022-33027

HIGH CVSS 7.8 Jun 23, 2022

LibreDWG v0.12.4.4608 contains a heap-use-after-free vulnerability in the dwg_add_handleref function that could allow attackers to execute arbitrary code or cause denial of service. This affects appli...

CVE-2022-33032

HIGH CVSS 7.8 Jun 23, 2022

LibreDWG v0.12.4.4608 contains a heap buffer overflow vulnerability in the decode_preR13_section_hdr function. This allows attackers to execute arbitrary code or cause denial of service by processing ...

CVE-2022-33034

HIGH CVSS 7.8 Jun 23, 2022

CVE-2022-33034 is a stack overflow vulnerability in LibreDWG's decode_r2007.c file that allows attackers to execute arbitrary code or cause denial of service by providing specially crafted DWG files. ...

CVE-2021-42585

HIGH CVSS 8.8 May 23, 2022

CVE-2021-42585 is a heap buffer overflow vulnerability in LibreDWG's dwgread library that allows remote code execution when processing malicious DWG files. This affects any application using LibreDWG ...

CVE-2021-28236

HIGH CVSS 7.5 Dec 2, 2021

LibreDWG v0.12.3 contains a NULL pointer dereference vulnerability in out_dxfb.c that can cause denial of service (DoS) through application crashes. This affects users and systems that process DWG fil...

CVE-2021-39528

HIGH CVSS 8.8 Sep 20, 2021

CVE-2021-39528 is a double-free vulnerability in LibreDWG's dwg_free_MATERIAL_private() function that can lead to memory corruption and potential remote code execution. This affects applications using...

CVE-2021-39522

HIGH CVSS 8.8 Sep 20, 2021

CVE-2021-39522 is a heap-based buffer overflow vulnerability in LibreDWG's bit_wcs2len() function. This allows attackers to execute arbitrary code or cause denial of service by processing specially cr...

CVE-2021-39525

HIGH CVSS 8.8 Sep 20, 2021

CVE-2021-39525 is a heap-based buffer overflow vulnerability in libredwg's bit_read_fixed() function. This allows attackers to execute arbitrary code or cause denial of service by processing specially...

CVE-2021-36080

HIGH CVSS 8.8 Jul 1, 2021

CVE-2021-36080 is a double-free vulnerability in GNU LibreDWG's bit_chain_free function that can lead to memory corruption and potential remote code execution. This affects applications that process D...

CVE-2020-21831

HIGH CVSS 8.8 May 17, 2021

A heap-based buffer overflow vulnerability in GNU LibreDWG 0.10 allows attackers to execute arbitrary code or cause denial of service by processing specially crafted DWG files. This affects any applic...

CVE-2020-21843

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21843 is a heap-based buffer overflow vulnerability in GNU LibreDWG 0.10, allowing attackers to execute arbitrary code or cause denial-of-service by processing malicious DWG files. It affects...

CVE-2020-21830

HIGH CVSS 8.8 May 17, 2021

A heap-based buffer overflow vulnerability in GNU LibreDWG 0.10 allows attackers to execute arbitrary code or cause denial of service by processing specially crafted DWG files. This affects any applic...

CVE-2020-21833

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21833 is a heap-based buffer overflow vulnerability in GNU LibreDWG's DWG file parser. Attackers can exploit this by crafting malicious DWG files to potentially execute arbitrary code or caus...

CVE-2020-21836

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21836 is a heap-based buffer overflow vulnerability in GNU LibreDWG's DWG file parser. Attackers can exploit this by crafting malicious DWG files to potentially execute arbitrary code or caus...

CVE-2020-21840

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21840 is a heap-based buffer overflow vulnerability in GNU LibreDWG's bit_search_sentinel function that allows attackers to execute arbitrary code or cause denial of service. This affects use...

CVE-2020-21814

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21814 is a heap-based buffer overflow vulnerability in GNU LibreDWG's htmlwescape function that allows attackers to execute arbitrary code or cause denial of service. This affects systems usi...

CVE-2020-21816

HIGH CVSS 8.8 May 17, 2021

CVE-2020-21816 is a heap-based buffer overflow vulnerability in GNU LibreDWG's HTML escape function that allows attackers to execute arbitrary code or cause denial of service. This affects application...

CVE-2020-21818

HIGH CVSS 8.8 May 17, 2021

A heap-based buffer overflow vulnerability in GNU LibreDWG allows attackers to execute arbitrary code or cause denial of service by processing specially crafted DWG files. This affects systems running...

CVE-2020-21813

HIGH CVSS 7.8 May 17, 2021

CVE-2020-21813 is a heap-based buffer overflow vulnerability in GNU LibreDWG's dwg2SVG converter. Attackers can exploit this by crafting malicious DWG files to execute arbitrary code or crash applicat...