Search CVE reports


Toggle filters

1 – 10 of 28 results


CVE-2025-31164

Medium priority
Needs evaluation

heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via  create_line_with_spline.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-31163

Medium priority
Needs evaluation

Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-31162

Medium priority
Needs evaluation

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-37530

Low priority
Needs evaluation

A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Needs evaluation Needs evaluation Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2021-37529

Low priority
Needs evaluation

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

1 affected package

fig2dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Needs evaluation Needs evaluation Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2021-32280

Medium priority

Some fixes available 2 of 4

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

3 affected packages

fig2dev, transfig, xfig

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Not affected Not affected Fixed Fixed Ignored
transfig Not in release Not in release Not in release Not in release Vulnerable
xfig Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-21535

Medium priority

Some fixes available 2 of 3

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

2 affected packages

fig2dev, transfig

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Not affected Not affected Fixed Fixed Ignored
transfig Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-21534

Medium priority

Some fixes available 2 of 3

fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

2 affected packages

fig2dev, transfig

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Not affected Not affected Fixed Fixed Ignored
transfig Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-21533

Medium priority

Some fixes available 2 of 3

fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.

2 affected packages

fig2dev, transfig

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Not affected Not affected Fixed Fixed Ignored
transfig Not in release Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2020-21532

Medium priority

Some fixes available 2 of 3

fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

2 affected packages

fig2dev, transfig

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
fig2dev Not affected Not affected Fixed Fixed Ignored
transfig Not in release Not in release Not in release Not in release Vulnerable
Show less packages