A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the openstream function in readpics.c.
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the freestream function in readpics.c, which could cause a denial of service (context-dependent).
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function computeclosedspline() located in transspline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.
fig2dev 3.2.7b contains a segmentation fault in the gencgmstart function in gencgm.c.
fig2dev 3.2.7b contains a global buffer overflow in the getline function in read.c.
fig2dev 3.2.7b contains a stack buffer overflow in the readtextobject function in read.c.
fig2dev 3.2.7b contains a segmentation fault in the readobjects function in read.c.
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
fig2dev 3.2.7b contains a stack buffer overflow in the bezierspline function in genepic.c.
fig2dev 3.2.7b contains a global buffer overflow in the convpatternindex function in gencgm.c.
A global buffer overflow in the genmpwritefontmacrolatex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.
A stack-based buffer overflow in the genptktext component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
A global buffer overflow in the setcolor component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
A stack-based buffer overflow in the putarrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
A global buffer overflow in the setfill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
A global buffer overflow in the putfont in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
A global buffer overflow in the shadeortintnameafterdeclarecolor in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
A stack-based buffer overflow in the genpstrxtext() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
readcolordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
makearrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calcarrow function in bound.c.
A buffer underwrite vulnerability in getline() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.