Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-31177 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. gnuplot is affected by a heap buffer overflow at function utf8_copy_one. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2025-31181 | A flaw was found in gnuplot. A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. NVD description · AI analysis pending | 6.2 | <1% |
| — | ||
| CVE-2020-25969 | gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-44917 | A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash. A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2021-29369 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-25412 +1 in the same advisory: …25559 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2018-19492 | An issue was discovered in cairo.trm in Gnuplot 5.2.5. An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend. NVD description · AI analysis pending | 7.8 | 2% | PoC |
| — | |
| CVE-2017-9670 | An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file. NVD description · AI analysis pending | 7.8 | <1% |
| — |