Vulnerabilities
Vulnerable Software
Gnu:  Security Vulnerabilities
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
CVSS Score
6.5
EPSS Score
0.015
Published
2020-07-17
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
CVSS Score
8.1
EPSS Score
0.012
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
CVSS Score
6.5
EPSS Score
0.01
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.
CVSS Score
8.8
EPSS Score
0.013
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
CVSS Score
8.1
EPSS Score
0.012
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
CVSS Score
9.8
EPSS Score
0.019
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
CVSS Score
8.1
EPSS Score
0.012
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
CVSS Score
7.5
EPSS Score
0.016
Published
2020-07-16
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
CVSS Score
4.3
EPSS Score
0.019
Published
2020-06-24
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its memory, causing it to allocate lots of memory, or perhaps overrunning a buffer. This is only possible with applications which make non-raw queries for SOA or RP records.
CVSS Score
9.8
EPSS Score
0.021
Published
2020-06-18


Contact Us

Shodan ® - All rights reserved