Where
-Infinity
0
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

1 / 2
Source: Ubuntu
First published (updated )
Severity
8.8
Null Pointer Dereference
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.

First published (updated )
Severity
1
Null Pointer Dereference

A NULL pointer dereference vulnerability was found in graphviz in the rebuildvlists function. A maliciously crafted file could cause the application to crash.

References:

https://issuetracker.google.com/issues/77810342

Upstream issue:

https://gitlab.com/graphviz/graphviz/issues/1367

First published (updated )
Severity
5.5
Null Pointer Dereference
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A NULL pointer dereference vulnerability was found in graphviz in the rebuildvlists function. A maliciously crafted file could cause the application to crash.

References:

https://issuetracker.google.com/issues/77810342

Upstream issue:

https://gitlab.com/graphviz/graphviz/issues/1367

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

First published (updated )
Severity
1
Buffer Overflow

Graphviz, a collection of tools for the manipulation and layout of graphs, was recently reported to be affected by a buffer overflow vulnerability from user input, which seem to be caused due to the acceptance of arbitrary long digit list by regex.

References: http://seclists.org/oss-sec/2014/q1/46

Commit: https://github.com/ellson/graphviz/commit/1d1bdec6318746f6f19f245db589eddc887ae8ff

First published (updated )
Severity
1
Buffer Overflow

Graphviz, a collection of tools for the manipulation and layout of graphs, was recently reported to be affected by a buffer overflow vulnerability, which seem to have introduced in the fix for CVE-2014-0978.

References: http://seclists.org/oss-sec/2014/q1/46

Commit: https://github.com/ellson/graphviz/commit/d266bb2b4154d11c27252b56d86963aef4434750

First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Graphviz, a collection of tools for the manipulation and layout of graphs, was recently reported to be affected by a buffer overflow vulnerability, which seem to have introduced in the fix for CVE-2014-0978.

References: http://seclists.org/oss-sec/2014/q1/46

Commit: https://github.com/ellson/graphviz/commit/d266bb2b4154d11c27252b56d86963aef4434750

1 / 2
Source: Red Hat
First published (updated )
Severity
1
Buffer Overflow

Graphviz, a collection of tools for the manipulation and layout of graphs, was recently reported to be affected by a buffer overflow vulnerability.

The vulnerability is caused due to an error within the "yyerror()" function (lib/cgraph/scan.l) and can be exploited to cause a stack-based buffer overflow via a specially crafted file.

References: https://bugs.gentoo.org/showbug.cgi?id=497274

Commit: https://github.com/ellson/graphviz/commit/7aaddf52cd98589fb0c3ab72a393f8411838438a

First published (updated )
Severity
8.5
Buffer Overflow
AV:N/AC:M/Au:S/C:C/I:C/A:C

Stack-based buffer overflow in the pushsubg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agrapht elements.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203