This page lists publicly disclosed CVE vulnerabilities affecting xfig_project xfig (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-45920 | Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager. | [email protected] | 4.2 | 0.01% | 2024-03-27 | 2025-11-04 |
| CVE-2021-40241 | xfig 3.2.7 is vulnerable to Buffer Overflow. | [email protected] | 9.8 | 0.40% | 2022-10-31 | 2025-05-07 |
| CVE-2019-19555 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. | [email protected] | 5.5 | 0.27% | 2019-12-04 | 2024-11-21 |
| CVE-2017-16899 | An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c. | [email protected] | 7.1 | 0.41% | 2017-11-20 | 2026-05-13 |