Skip to main content

Vendor/product archive

gnu / libredwg CVEs

Beta · best-effort

88 CVEs tagged to gnu / libredwg5 Critical, 60 High, 23 Medium, 0 Low, 0 Unrated.

CVE-2025-61154

Published Mar 12, 2026

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26157

Published Jan 2, 2024

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36274

Published Jun 23, 2023

LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36273

Published Jun 23, 2023

LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36272

Published Jun 23, 2023

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36271

Published Jun 23, 2023

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25222

Published Mar 1, 2023

A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45332

Published Nov 30, 2022

LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35164

Published Aug 18, 2022

LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-33034

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33033

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33032

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33028

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33027

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33026

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33025

Published Jun 23, 2022

LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33024

Published Jun 23, 2022

There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libred…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42586

Published May 23, 2022

A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42585

Published May 23, 2022

A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45950

Published Jan 1, 2022

LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28237

Published Dec 2, 2021

LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28236

Published Dec 2, 2021

LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39530

Published Sep 20, 2021

An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39528

Published Sep 20, 2021

An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39527

Published Sep 20, 2021

An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 88 CVEsPage 1 of 4