Vulnerabilities
Vulnerable Software
Gnu:  Security Vulnerabilities
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
CVSS Score
8.8
EPSS Score
0.003
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-09-20
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-09-20
An issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.
CVSS Score
8.8
EPSS Score
0.004
Published
2021-09-20
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-09-03
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-08-12


Contact Us

Shodan ® - All rights reserved