Show filters
1,191 Total Results
Displaying 331-340 of 1,191
Sort by:
Attacker Value
Unknown

CVE-2020-6614

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
Attacker Value
Unknown

CVE-2020-6615

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).
Attacker Value
Unknown

CVE-2019-14866

Disclosure Date: January 07, 2020 (last updated February 21, 2025)
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting those archives from a high-privilege user without carefully reviewing them may lead to the compromise of the system.
Attacker Value
Unknown

CVE-2019-20015

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
Attacker Value
Unknown

CVE-2019-20012

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
Attacker Value
Unknown

CVE-2019-20009

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
Attacker Value
Unknown

CVE-2019-20013

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
Attacker Value
Unknown

CVE-2019-20011

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
Attacker Value
Unknown

CVE-2019-20014

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
Attacker Value
Unknown

CVE-2019-20010

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.