Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.79% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | |
| Modificada | Alta (7.8) | 0.79% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c. | |
| Modificada | Alta (7.5) | 1.1% | — | GNU Libredwg | 23/6/2022 | 17/6/2026 | There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608. | |
| Modificada | Alta (8.8) | 1.0% | — | GNU Libredwg | 23/5/2022 | 17/6/2026 | A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | |
| Modificada | Alta (8.8) | 1.0% | — | GNU Libredwg | 23/5/2022 | 17/6/2026 | A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | |
| Modificada | Media (6.5) | 0.89% | — | GNU Libredwg | 1/1/2022 | 17/6/2026 | LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object). | |
| Modificada | Crítica (9.8) | 1.4% | — | GNU Libredwg | 2/12/2021 | 17/6/2026 | LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. | |
| Modificada | Alta (7.5) | 1.2% | — | GNU Libredwg | 2/12/2021 | 17/6/2026 | LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.87% | — | GNU Libredwg | 20/9/2021 | 17/6/2026 | An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service. | |
| Modificada | Alta (8.8) | 1.3% | — | GNU Libredwg | 1/7/2021 | 17/6/2026 | GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object). | |
| Modificada | Media (5.5) | 0.63% | — | GNU Libredwg | 18/5/2021 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985. | |
| Modificada | Media (6.5) | 0.92% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638. |