Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.2)0.23%—Xfig Project Xfig27/3/202417/6/2026
Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager.
ModificadaCrítica (9.8)1.0%—Xfig Project Xfig31/10/202217/6/2026
xfig 3.2.7 is vulnerable to Buffer Overflow.
ModificadaMedia (5.5)0.98%—Xfig Project Fig2devDebian Linux20/9/202117/6/2026
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
ModificadaMedia (5.5)0.89%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
ModificadaMedia (5.5)0.87%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
ModificadaMedia (5.5)0.87%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
ModificadaMedia (5.5)1.1%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
ModificadaMedia (5.5)1.1%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
ModificadaMedia (5.5)0.72%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
ModificadaMedia (5.5)1.1%—Xfig Project Fig2devDebian Linux16/9/202117/6/2026
fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
ModificadaMedia (5.5)1.2%—Xfig Project Fig2devFedoraproject FedoraDebian Linux15/12/201917/6/2026
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
ModificadaMedia (5.5)1.1%—Xfig Project Xfig4/12/201917/6/2026
read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
ModificadaMedia (5.5)1.2%—Xfig Project Fig2devDebian LinuxOpensuse Leap26/7/201917/6/2026
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
ModificadaAlta (7.1)1.4%—Xfig Project XfigDebian Linux20/11/201717/6/2026
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.
ModificadaMedia (6.8)5.8%—Xfig17/12/201016/6/2026
Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.
ModificadaMedia (4.3)1.7%—Xfig8/12/200916/6/2026
Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses the 1.3 file format, possibly related to the readfp_fig function in f_read.c.
ModificadaMedia (6.8)11%—Xfig8/12/200916/6/2026
Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file…
ModificadaMedia (4.4)0.33%—XfigDebian Linux8/6/200916/6/2026
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or…