← Back

Dia

dia

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Dia
dia

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dia
1Dia
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related t...Show more
Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).Show less
1Dia
1Dia
Apr 23, 2026
Jun 26, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulnerable FreeType libraries that contain CVE-2007-2754 and/or CVE-2007-1351.
1Dia
1Dia
Apr 16, 2026
May 28, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.
1Dia
1Dia
Apr 16, 2026
May 19, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifie...Show more
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.Show less
1Dia
1Dia
Apr 16, 2026
Mar 30, 2006
N/A· v4
N/A· v3
7.6 HIGH· v2
Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1)...Show more
Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.Show less
1Dia
1Dia
Apr 16, 2026
Oct 5, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.