ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-46397
+3 in the same advisory: …46398 …46399 …46400
A flaw was found in xfig.

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • fig2dev project fig2dev
  • fig2dev project enterprise linux
CVE-2025-31164
+2 in the same advisory: …31163 …31162
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.

heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.

NVD description · AI analysis pending
6.6<1% PoC
  • fig2dev project fig2dev
CVE-2021-37530
+1 in the same advisory: …37529
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

NVD description · AI analysis pending
5.5<1% PoC
  • fig2dev project fig2dev
  • fig2dev project debian linux
CVE-2020-21676
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via conver

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

NVD description · AI analysis pending
5.51% PoC
  • fig2dev project fig2dev
  • fig2dev project debian linux
CVE-2021-3561
An Out of Bounds flaw was found fig2dev version 3.2.8a.

An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

NVD description · AI analysis pending
7.11% PoC
  • fig2dev project fig2dev
  • fig2dev project fedora
  • fig2dev project debian linux
CVE-2019-19746
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.

make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.

NVD description · AI analysis pending
5.51% PoC
  • fig2dev project fig2dev
  • fig2dev project fedora
CVE-2018-16140
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig f

A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.

NVD description · AI analysis pending
7.81%
  • canonical ubuntu linux
  • canonical fig2dev