fig2dev project records
20 published records for vendor fig2dev project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-787 Out-of-bounds Write5
- CWE-476 NULL Pointer Dereference3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-369 Divide By Zero1
- CWE-415 Double Free1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2018-16140No exploit | A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer canonical · ubuntu linux · CWE-787 | High7.8 | — | 1.4% | Aug 29, 2018 |
31Monitor | CVE-2025-46397No exploit | Xfig: xfig: stack-overflow allows possible code execution via local input manipulationfig2dev project · fig2dev · CWE-120 | High7.8 | — | 0.3% | Apr 23, 2025 |
28Monitor | CVE-2021-3561No exploit | An Out of Bounds flaw was found fig2dev version 3.2.8a.fig2dev project · fig2dev · CWE-119 | High7.1 | — | 1.2% | May 26, 2021 |
26Monitor | CVE-2025-31164No exploit | fig2dev heap-buffer overflowfig2dev project · fig2dev · CWE-122 | Medium6.6 | — | 0.2% | Mar 28, 2025 |
26Monitor | CVE-2025-31163No exploit | fig2dev segmentation faultfig2dev project · fig2dev · CWE-476 | Medium6.6 | — | 0.2% | Mar 28, 2025 |
26Monitor | CVE-2025-31162No exploit | fig2dev float point exceptionfig2dev project · fig2dev · CWE-369 | Medium6.6 | — | 0.2% | Mar 28, 2025 |
22Monitor | CVE-2019-19746No exploit | make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large fig2dev project · fig2dev · CWE-190 | Medium5.5 | — | 1.2% | Dec 11, 2019 |
22Monitor | CVE-2020-21676No exploit | A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of servfig2dev project · fig2dev · CWE-787 | Medium5.5 | — | 1.1% | Aug 10, 2021 |
22Monitor | CVE-2020-21675No exploit | A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS)fig2dev project · fig2dev · CWE-787 | Medium5.5 | — | 1.1% | Aug 10, 2021 |
22Monitor | CVE-2020-21682No exploit | A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via convfig2dev project · fig2dev · CWE-120 | Medium5.5 | — | 0.8% | Aug 10, 2021 |
22Monitor | CVE-2020-21683No exploit | A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denialfig2dev project · fig2dev · CWE-120 | Medium5.5 | — | 0.8% | Aug 10, 2021 |
22Monitor | CVE-2020-21680No exploit | A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (Dfig2dev project · fig2dev · CWE-787 | Medium5.5 | — | 0.8% | Aug 10, 2021 |
22Monitor | CVE-2021-37529No exploit | A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a fig2dev project · fig2dev · CWE-415 | Medium5.5 | — | 0.7% | Jan 12, 2022 |
22Monitor | CVE-2021-37530No exploit | A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.fig2dev project · fig2dev · CWE-787 | Medium5.5 | — | 0.7% | Jan 12, 2022 |
22Monitor | CVE-2020-21681No exploit | A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via config2dev project · fig2dev · CWE-120 | Medium5.5 | — | 0.7% | Aug 10, 2021 |
22Monitor | CVE-2020-21684No exploit | A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via convertingfig2dev project · fig2dev · CWE-120 | Medium5.5 | — | 0.7% | Aug 10, 2021 |
22Monitor | CVE-2020-21678No exploit | A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of servfig2dev project · fig2dev · CWE-120 | Medium5.5 | — | 0.7% | Aug 10, 2021 |
22Monitor | CVE-2025-46398No exploit | Xfig: fig2dev stack-overflow via read_objectsfig2dev project · fig2dev · CWE-121 | Medium5.5 | — | 0.3% | Apr 23, 2025 |
22Monitor | CVE-2025-46399No exploit | Xfig: transfig: fig2dev segmentation fault vulnerabilityfig2dev project · fig2dev · CWE-476 | Medium5.5 | — | 0.2% | Apr 23, 2025 |
22Monitor | CVE-2025-46400No exploit | Xfig: fig2dev segmentation fault in read_arcobjectfig2dev project · fig2dev · CWE-476 | Medium5.5 | — | 0.2% | Apr 23, 2025 |
- CVE-2018-1614031Monitor
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer
HighCVSS 7.8No exploitEPSS 1%canonical · ubuntu linuxAug 29, 2018
- CVE-2025-4639731Monitor
Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
HighCVSS 7.8No exploitEPSS 0%fig2dev project · fig2devApr 23, 2025
- CVE-2021-356128Monitor
An Out of Bounds flaw was found fig2dev version 3.2.8a.
HighCVSS 7.1No exploitEPSS 1%fig2dev project · fig2devMay 26, 2021
- CVE-2025-3116426Monitor
fig2dev heap-buffer overflow
MediumCVSS 6.6No exploitEPSS 0%fig2dev project · fig2devMar 28, 2025
- CVE-2025-3116326Monitor
fig2dev segmentation fault
MediumCVSS 6.6No exploitEPSS 0%fig2dev project · fig2devMar 28, 2025
- CVE-2025-3116226Monitor
fig2dev float point exception
MediumCVSS 6.6No exploitEPSS 0%fig2dev project · fig2devMar 28, 2025
- CVE-2019-1974622Monitor
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devDec 11, 2019
- CVE-2020-2167622Monitor
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of serv
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2167522Monitor
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS)
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2168222Monitor
A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via conv
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2168322Monitor
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2168022Monitor
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (D
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2021-3752922Monitor
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devJan 12, 2022
- CVE-2021-3753022Monitor
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devJan 12, 2022
- CVE-2020-2168122Monitor
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via con
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2168422Monitor
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2020-2167822Monitor
A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of serv
MediumCVSS 5.5No exploitEPSS 1%fig2dev project · fig2devAug 10, 2021
- CVE-2025-4639822Monitor
Xfig: fig2dev stack-overflow via read_objects
MediumCVSS 5.5No exploitEPSS 0%fig2dev project · fig2devApr 23, 2025
- CVE-2025-4639922Monitor
Xfig: transfig: fig2dev segmentation fault vulnerability
MediumCVSS 5.5No exploitEPSS 0%fig2dev project · fig2devApr 23, 2025
- CVE-2025-4640022Monitor
Xfig: fig2dev segmentation fault in read_arcobject
MediumCVSS 5.5No exploitEPSS 0%fig2dev project · fig2devApr 23, 2025