Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-46045

Disclosure Date: February 02, 2024 (last updated March 07, 2024)
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
Attacker Value
Unknown

CVE-2020-18032

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Attacker Value
Unknown

CVE-2019-11023

Disclosure Date: April 08, 2019 (last updated November 08, 2023)
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.
0
Attacker Value
Unknown

CVE-2019-9904

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
Attacker Value
Unknown

CVE-2018-10196

Disclosure Date: May 30, 2018 (last updated November 08, 2023)
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.
0
Attacker Value
Unknown

CVE-2014-1235

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-0978.
0
Attacker Value
Unknown

CVE-2014-9157

Disclosure Date: December 03, 2014 (last updated July 20, 2024)
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
0
Attacker Value
Unknown

CVE-2014-0978

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file.
0
Attacker Value
Unknown

CVE-2014-1236

Disclosure Date: January 10, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list."
0
Attacker Value
Unknown

CVE-2008-4555

Disclosure Date: October 14, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.
0