Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.23% | — | Xfig Project Xfig | 27/3/2024 | 17/6/2026 | Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager. | |
| Modificada | Crítica (9.8) | 1.0% | — | Xfig Project Xfig | 31/10/2022 | 17/6/2026 | xfig 3.2.7 is vulnerable to Buffer Overflow. | |
| Modificada | Media (5.5) | 0.98% | — | Xfig Project Fig2devDebian Linux | 20/9/2021 | 17/6/2026 | An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8. | |
| Modificada | Media (5.5) | 0.89% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c. | |
| Modificada | Media (5.5) | 0.87% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c. | |
| Modificada | Media (5.5) | 0.87% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c. | |
| Modificada | Media (5.5) | 1.1% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c. | |
| Modificada | Media (5.5) | 1.1% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c. | |
| Modificada | Media (5.5) | 0.72% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. | |
| Modificada | Media (5.5) | 1.1% | — | Xfig Project Fig2devDebian Linux | 16/9/2021 | 17/6/2026 | fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. | |
| Modificada | Media (5.5) | 1.2% | — | Xfig Project Fig2devFedoraproject FedoraDebian Linux | 15/12/2019 | 17/6/2026 | read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. | |
| Modificada | Media (5.5) | 1.1% | — | Xfig Project Xfig | 4/12/2019 | 17/6/2026 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. | |
| Modificada | Media (5.5) | 1.2% | — | Xfig Project Fig2devDebian LinuxOpensuse Leap | 26/7/2019 | 17/6/2026 | Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. | |
| Modificada | Alta (7.1) | 1.4% | — | Xfig Project XfigDebian Linux | 20/11/2017 | 17/6/2026 | An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c. | |
| Modificada | Media (6.8) | 5.8% | — | Xfig | 17/12/2010 | 16/6/2026 | Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition. | |
| Modificada | Media (4.3) | 1.7% | — | Xfig | 8/12/2009 | 16/6/2026 | Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses the 1.3 file format, possibly related to the readfp_fig function in f_read.c. | |
| Modificada | Media (6.8) | 11% | — | Xfig | 8/12/2009 | 16/6/2026 | Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file… | |
| Modificada | Media (4.4) | 0.33% | — | XfigDebian Linux | 8/6/2009 | 16/6/2026 | Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or… |