Записи graphviz
11 опубликованных записей вендора graphviz.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 90,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-476 NULL Pointer Dereference2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-125 Out-of-bounds Read1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-674 Uncontrolled Recursion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2014-1236Эксплойта нет | Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impacgraphviz · graphviz · CWE-119 | Критическая10,0 | — | 6,1 % | 10 янв. 2014 г. |
38Наблюдать | CVE-2014-0978Эксплойта нет | Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impagraphviz · graphviz · CWE-119 | Критическая9,3 | — | 4,9 % | 10 янв. 2014 г. |
36Наблюдать | CVE-2008-4555Эксплойта нет | Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, algraphviz · graphviz · CWE-119 | Высокая8,5 | — | 5,1 % | 14 окт. 2008 г. |
36Наблюдать | CVE-2019-11023Эксплойта нет | The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphgraphviz · graphviz · CWE-476 | Высокая8,8 | — | 4,9 % | 8 апр. 2019 г. |
32Наблюдать | CVE-2014-9157Эксплойта нет | Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via graphviz · graphviz · CWE-134 | Высокая7,5 | — | 5,6 % | 3 дек. 2014 г. |
32Наблюдать | CVE-2014-1235Эксплойта нет | Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denialgraphviz · graphviz · CWE-119 | Высокая7,8 | — | 2,9 % | 7 авг. 2017 г. |
32Наблюдать | CVE-2020-18032Эксплойта нет | Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code graphviz · graphviz · CWE-120 | Высокая7,8 | — | 2,6 % | 29 апр. 2021 г. |
31Наблюдать | CVE-2023-46045Эксплойта нет | Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.graphviz · graphviz · CWE-125 | Высокая7,8 | — | 0,8 % | 2 февр. 2024 г. |
27Наблюдать | CVE-2019-9904Эксплойта нет | An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.graphviz · graphviz · CWE-674 | Средняя6,5 | — | 2,7 % | 21 мар. 2019 г. |
23Наблюдать | CVE-2018-10196Эксплойта нет | NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows rgraphviz · graphviz · CWE-476 | Средняя5,5 | — | 1,7 % | 30 мая 2018 г. |
14Наблюдать | CVE-2005-4803Эксплойта нет | graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.graphviz · graphviz | Низкая3,6 | — | 0,4 % | 31 дек. 2005 г. |
- CVE-2014-123642В плане
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impac
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %graphviz · graphviz10 янв. 2014 г.
- CVE-2014-097838Наблюдать
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impa
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %graphviz · graphviz10 янв. 2014 г.
- CVE-2008-455536Наблюдать
Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, al
ВысокаяCVSS 8,5Эксплойта нетEPSS 5 %graphviz · graphviz14 окт. 2008 г.
- CVE-2019-1102336Наблюдать
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graph
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %graphviz · graphviz8 апр. 2019 г.
- CVE-2014-915732Наблюдать
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %graphviz · graphviz3 дек. 2014 г.
- CVE-2014-123532Наблюдать
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %graphviz · graphviz7 авг. 2017 г.
- CVE-2020-1803232Наблюдать
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %graphviz · graphviz29 апр. 2021 г.
- CVE-2023-4604531Наблюдать
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %graphviz · graphviz2 февр. 2024 г.
- CVE-2019-990427Наблюдать
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.
СредняяCVSS 6,5Эксплойта нетEPSS 3 %graphviz · graphviz21 мар. 2019 г.
- CVE-2018-1019623Наблюдать
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows r
СредняяCVSS 5,5Эксплойта нетEPSS 2 %graphviz · graphviz30 мая 2018 г.
- CVE-2005-480314Наблюдать
graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %graphviz · graphviz31 дек. 2005 г.