📦

libredwg

Vendor: gnu

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 15 Remote Access
Total CVEs 155 Total Indexed
Avg. EPSS 1.29% Exploit Prob.
Latest CVE CVE-2025-61154 Mar 12

Security Vulnerability Index

Page 2 / 16
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

EPSS: 0.71%
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.

EPSS: 0.71%
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.

EPSS: 0.71%
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.

EPSS: 0.75%
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

EPSS: 0.71%
7.8 CVSS

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.

EPSS: 0.79%
7.5 CVSS

There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.

EPSS: 1.01%
8.8 CVSS

A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

EPSS: 0.99%
8.8 CVSS

A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

EPSS: 0.97%
6.5 CVSS

LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

EPSS: 0.89%