← Back

Librecad

librecad

8 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Librecad
librecad
Libdxfrw
libdxfrw

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Librecad
1Librecad
Nov 21, 2024
Jun 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information via a crafted DBF file.
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibrecad
Nov 21, 2024
Jan 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibrecad
Nov 21, 2024
Jan 25, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibrecad
Nov 21, 2024
Jan 25, 2022
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibdxfrw
Nov 21, 2024
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can prov...Show more
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibdxfrw
Nov 21, 2024
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can prov...Show more
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibdxfrw
Nov 21, 2024
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can pro...Show more
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Librecad
1Librecad
Nov 21, 2024
Nov 8, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly have unspecified other impact via a crafted file.