Skip to content
Noroxi

graphviz records

11 published records for vendor graphviz.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
90.9%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impac

    CriticalCVSS 10.0No exploitEPSS 6%

    graphviz · graphvizJan 10, 2014

  • CVE-2014-0978
    38Monitor

    Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impa

    CriticalCVSS 9.3No exploitEPSS 5%

    graphviz · graphvizJan 10, 2014

  • CVE-2008-4555
    36Monitor

    Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, al

    HighCVSS 8.5No exploitEPSS 5%

    graphviz · graphvizOct 14, 2008

  • The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graph

    HighCVSS 8.8No exploitEPSS 5%

    graphviz · graphvizApr 8, 2019

  • CVE-2014-9157
    32Monitor

    Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via

    HighCVSS 7.5No exploitEPSS 6%

    graphviz · graphvizDec 3, 2014

  • CVE-2014-1235
    32Monitor

    Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial

    HighCVSS 7.8No exploitEPSS 3%

    graphviz · graphvizAug 7, 2017

  • Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code

    HighCVSS 7.8No exploitEPSS 3%

    graphviz · graphvizApr 29, 2021

  • Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.

    HighCVSS 7.8No exploitEPSS 1%

    graphviz · graphvizFeb 2, 2024

  • CVE-2019-9904
    27Monitor

    An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.

    MediumCVSS 6.5No exploitEPSS 3%

    graphviz · graphvizMar 21, 2019

  • NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows r

    MediumCVSS 5.5No exploitEPSS 2%

    graphviz · graphvizMay 30, 2018

  • CVE-2005-4803
    14Monitor

    graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    LowCVSS 3.6No exploitEPSS 0%

    graphviz · graphvizDec 31, 2005