Vulnerabilities
Vulnerable Software
Graphviz:  >> Graphviz  >> 2.34.0  Security Vulnerabilities
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
CVSS Score
7.8
EPSS Score
0.005
Published
2021-04-29
Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-0978.
CVSS Score
7.8
EPSS Score
0.012
Published
2017-08-07
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
CVSS Score
7.5
EPSS Score
0.019
Published
2014-12-03
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file.
CVSS Score
9.3
EPSS Score
0.076
Published
2014-01-10
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list."
CVSS Score
10.0
EPSS Score
0.079
Published
2014-01-10


Contact Us

Shodan ® - All rights reserved