Libredwg
GNU · 90 CVEs
GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference
Sep 14, 2026
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
Jul 13, 2026
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
Jul 9, 2026
GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
Jul 9, 2026
GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
May 26, 2026
GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds
May 26, 2026
GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
May 26, 2026
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
May 25, 2026
GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference
May 25, 2026
GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow
May 25, 2026
GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
May 25, 2026
GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
May 25, 2026
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to ca…
Mar 12, 2026
Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds r…
Jan 2, 2024
LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
Jun 23, 2023
LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
Jun 23, 2023
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
Jun 23, 2023
LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
Jun 23, 2023
A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.
Mar 1, 2023
LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at de…
Nov 30, 2022
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
Aug 18, 2022
LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
Jun 22, 2022
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
Jun 22, 2022
LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at de…
Jun 22, 2022
LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_…
Jun 22, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-90622 | GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference | MEDIUM | 0.17% | Sep 14, 2026 |
| CVE-2026-15520 | GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow | MEDIUM | 0.18% | Jul 13, 2026 |
| CVE-2026-15184 | GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference | MEDIUM | 0.17% | Jul 9, 2026 |
| CVE-2026-15182 | GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow | MEDIUM | 0.18% | Jul 9, 2026 |
| CVE-2026-9605 | GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow | MEDIUM | 0.57% | May 26, 2026 |
| CVE-2026-9530 | GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds | MEDIUM | 0.16% | May 26, 2026 |
| CVE-2026-9529 | GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference | MEDIUM | 0.16% | May 26, 2026 |
| CVE-2026-9504 | GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds | MEDIUM | 0.16% | May 25, 2026 |
| CVE-2026-9503 | GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference | MEDIUM | 0.16% | May 25, 2026 |
| CVE-2026-9502 | GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow | MEDIUM | 0.17% | May 25, 2026 |
| CVE-2026-9501 | GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion | MEDIUM | 0.16% | May 25, 2026 |
| CVE-2026-9500 | GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow | MEDIUM | 0.17% | May 25, 2026 |
| CVE-2025-61154 | Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the fu… | MEDIUM | 0.22% | Mar 12, 2026 |
| CVE-2023-26157 | Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in deco… | HIGH | 0.54% | Jan 2, 2024 |
| CVE-2023-36274 | LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c. | HIGH | 0.92% | Jun 23, 2023 |
| CVE-2023-36273 | LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c. | HIGH | 0.70% | Jun 23, 2023 |
| CVE-2023-36272 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c. | HIGH | 0.92% | Jun 23, 2023 |
| CVE-2023-36271 | LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c. | HIGH | 0.92% | Jun 23, 2023 |
| CVE-2023-25222 | A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c. | HIGH | 0.81% | Mar 1, 2023 |
| CVE-2022-45332 | LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c. | HIGH | 0.31% | Nov 30, 2022 |
| CVE-2022-35164 | LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. | CRITICAL | 1.02% | Aug 18, 2022 |
| CVE-2022-33034 | LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. | HIGH | 0.75% | Jun 22, 2022 |
| CVE-2022-33033 | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. | HIGH | 0.75% | Jun 22, 2022 |
| CVE-2022-33032 | LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c. | HIGH | 0.75% | Jun 22, 2022 |
| CVE-2022-33025 | LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c. | HIGH | 0.79% | Jun 22, 2022 |
Showing 1 to 25 of 90 CVEs