Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-46045
Disclosure Date: February 02, 2024 (last updated March 07, 2024)
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
0
Attacker Value
Unknown
CVE-2020-18032
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
0
Attacker Value
Unknown
CVE-2019-11023
Disclosure Date: April 08, 2019 (last updated November 08, 2023)
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.
0
Attacker Value
Unknown
CVE-2019-9904
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
0
Attacker Value
Unknown
CVE-2018-10196
Disclosure Date: May 30, 2018 (last updated November 08, 2023)
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.
0
Attacker Value
Unknown
CVE-2014-1235
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-0978.
0
Attacker Value
Unknown
CVE-2014-9157
Disclosure Date: December 03, 2014 (last updated July 20, 2024)
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
0
Attacker Value
Unknown
CVE-2014-0978
Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file.
0
Attacker Value
Unknown
CVE-2014-1236
Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list."
0
Attacker Value
Unknown
CVE-2008-4555
Disclosure Date: October 14, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.
0