graphviz kayıtları
graphviz üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %90,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-476 NULL Pointer Dereference2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-125 Out-of-bounds Read1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-674 Uncontrolled Recursion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2014-1236İstismar yok | Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impacgraphviz · graphviz · CWE-119 | Kritik10,0 | — | %6,1 | 10 Oca 2014 |
38İzleyin | CVE-2014-0978İstismar yok | Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impagraphviz · graphviz · CWE-119 | Kritik9,3 | — | %4,9 | 10 Oca 2014 |
36İzleyin | CVE-2008-4555İstismar yok | Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, algraphviz · graphviz · CWE-119 | Yüksek8,5 | — | %5,1 | 14 Eki 2008 |
36İzleyin | CVE-2019-11023İstismar yok | The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphgraphviz · graphviz · CWE-476 | Yüksek8,8 | — | %4,9 | 8 Nis 2019 |
32İzleyin | CVE-2014-9157İstismar yok | Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via graphviz · graphviz · CWE-134 | Yüksek7,5 | — | %5,6 | 3 Ara 2014 |
32İzleyin | CVE-2014-1235İstismar yok | Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denialgraphviz · graphviz · CWE-119 | Yüksek7,8 | — | %2,9 | 7 Ağu 2017 |
32İzleyin | CVE-2020-18032İstismar yok | Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code graphviz · graphviz · CWE-120 | Yüksek7,8 | — | %2,6 | 29 Nis 2021 |
31İzleyin | CVE-2023-46045İstismar yok | Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.graphviz · graphviz · CWE-125 | Yüksek7,8 | — | %0,8 | 2 Şub 2024 |
27İzleyin | CVE-2019-9904İstismar yok | An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.graphviz · graphviz · CWE-674 | Orta6,5 | — | %2,7 | 21 Mar 2019 |
23İzleyin | CVE-2018-10196İstismar yok | NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows rgraphviz · graphviz · CWE-476 | Orta5,5 | — | %1,7 | 30 May 2018 |
14İzleyin | CVE-2005-4803İstismar yok | graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.graphviz · graphviz | Düşük3,6 | — | %0,4 | 31 Ara 2005 |
- CVE-2014-123642Planlayın
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impac
KritikCVSS 10,0İstismar yokEPSS %6graphviz · graphviz10 Oca 2014
- CVE-2014-097838İzleyin
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impa
KritikCVSS 9,3İstismar yokEPSS %5graphviz · graphviz10 Oca 2014
- CVE-2008-455536İzleyin
Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, al
YüksekCVSS 8,5İstismar yokEPSS %5graphviz · graphviz14 Eki 2008
- CVE-2019-1102336İzleyin
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graph
YüksekCVSS 8,8İstismar yokEPSS %5graphviz · graphviz8 Nis 2019
- CVE-2014-915732İzleyin
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via
YüksekCVSS 7,5İstismar yokEPSS %6graphviz · graphviz3 Ara 2014
- CVE-2014-123532İzleyin
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial
YüksekCVSS 7,8İstismar yokEPSS %3graphviz · graphviz7 Ağu 2017
- CVE-2020-1803232İzleyin
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code
YüksekCVSS 7,8İstismar yokEPSS %3graphviz · graphviz29 Nis 2021
- CVE-2023-4604531İzleyin
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.
YüksekCVSS 7,8İstismar yokEPSS %1graphviz · graphviz2 Şub 2024
- CVE-2019-990427İzleyin
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.
OrtaCVSS 6,5İstismar yokEPSS %3graphviz · graphviz21 Mar 2019
- CVE-2018-1019623İzleyin
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows r
OrtaCVSS 5,5İstismar yokEPSS %2graphviz · graphviz30 May 2018
- CVE-2005-480314İzleyin
graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
DüşükCVSS 3,6İstismar yokEPSS %0graphviz · graphviz31 Ara 2005