librecad records
8 published records for vendor librecad.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-125 Out-of-bounds Read1
- CWE-416 Use After Free1
- CWE-476 NULL Pointer Dereference1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2021-45341No exploit | A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Colibrecad · librecad · CWE-120 | High8.8 | — | 6.6% | Jan 25, 2022 |
36Monitor | CVE-2021-21899No exploit | A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.librecad · libdxfrw · CWE-119 | High8.8 | — | 2.8% | Nov 19, 2021 |
36Monitor | CVE-2021-21898No exploit | A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.librecad · libdxfrw · CWE-119 | High8.8 | — | 2.6% | Nov 19, 2021 |
36Monitor | CVE-2021-21900No exploit | A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.librecad · libdxfrw · CWE-416 | High8.8 | — | 2.5% | Nov 19, 2021 |
32Monitor | CVE-2021-45342No exploit | A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Colibrecad · librecad · CWE-120 | High7.8 | — | 1.9% | Jan 25, 2022 |
31Monitor | CVE-2018-19105No exploit | LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly halibrecad · librecad · CWE-787 | High7.8 | — | 1.5% | Nov 8, 2018 |
22Monitor | CVE-2021-45343No exploit | In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted librecad · librecad · CWE-476 | Medium5.5 | — | 0.9% | Jan 25, 2022 |
22Monitor | CVE-2023-30259No exploit | A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information via a crafted DBF fillibrecad · librecad · CWE-125 | Medium5.5 | — | 0.3% | Jun 28, 2023 |
- CVE-2021-4534137Monitor
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Co
HighCVSS 8.8No exploitEPSS 7%librecad · librecadJan 25, 2022
- CVE-2021-2189936Monitor
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.
HighCVSS 8.8No exploitEPSS 3%librecad · libdxfrwNov 19, 2021
- CVE-2021-2189836Monitor
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.
HighCVSS 8.8No exploitEPSS 3%librecad · libdxfrwNov 19, 2021
- CVE-2021-2190036Monitor
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580.
HighCVSS 8.8No exploitEPSS 3%librecad · libdxfrwNov 19, 2021
- CVE-2021-4534232Monitor
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Co
HighCVSS 7.8No exploitEPSS 2%librecad · librecadJan 25, 2022
- CVE-2018-1910531Monitor
LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly ha
HighCVSS 7.8No exploitEPSS 2%librecad · librecadNov 8, 2018
- CVE-2021-4534322Monitor
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted
MediumCVSS 5.5No exploitEPSS 1%librecad · librecadJan 25, 2022
- CVE-2023-3025922Monitor
A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information via a crafted DBF fil
MediumCVSS 5.5No exploitEPSS 0%librecad · librecadJun 28, 2023