Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-42702

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
Attacker Value
Unknown

CVE-2021-42700

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
Attacker Value
Unknown

CVE-2021-42704

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
Attacker Value
Unknown

CVE-2012-6076

Disclosure Date: March 12, 2013 (last updated October 05, 2023)
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.
0
Attacker Value
Unknown

CVE-2012-5656

Disclosure Date: January 18, 2013 (last updated February 16, 2024)
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
Attacker Value
Unknown

CVE-2007-1463

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.
0
Attacker Value
Unknown

CVE-2007-1464

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2005-3885

Disclosure Date: November 29, 2005 (last updated February 22, 2025)
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
0
Attacker Value
Unknown

CVE-2005-3737

Disclosure Date: November 22, 2005 (last updated February 22, 2025)
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
0