📦

libredwg

Vendor: gnu

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 15 Remote Access
Total CVEs 155 Total Indexed
Avg. EPSS 1.29% Exploit Prob.
Latest CVE CVE-2025-61154 Mar 12

Security Vulnerability Index

Page 4 / 16
5.5 CVSS

A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, which causes a denial of service by submitting a dwg file.

EPSS: 0.63%
8.8 CVSS

GNU LibreDWG 0.10 is affected by: memcpy-param-overlap. The impact is: execute arbitrary code (remote). The component is: read_2004_section_header ../../src/decode.c:2580.

EPSS: 1.51%
8.8 CVSS

A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_RC ../../src/bits.c:318.

EPSS: 1.12%
8.8 CVSS

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.

EPSS: 1.12%
8.8 CVSS
CVE-2020-21831
Exploit Found

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_handles ../../src/decode.c:2637.

EPSS: 1.06%
8.8 CVSS

A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_read_B ../../src/bits.c:135.

EPSS: 1.06%
8.8 CVSS

A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985.

EPSS: 1.06%
6.5 CVSS

An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.

EPSS: 0.91%
8.8 CVSS

A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842.

EPSS: 1.06%
8.8 CVSS

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175.

EPSS: 1.06%