Diagon Project maintains a visualization and diagram-generation tool whose vulnerability profile centers on memory-safety issues affecting its core product, including heap-based buffer overflows, improper memory-buffer boundary validation, array-index validation failures, and out-of-bounds write conditions. These weakness classes reflect the computational demands of processing and rendering structured data, and defenders should treat memory-corruption flaws in this tool as requiring attention wherever it processes untrusted input. Current exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diagon Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31194HIGH An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. | Jul 5, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-27390HIGH A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution | Jul 5, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diagon Project.
Media articles that mention a CVE ID that affects a product developed by Diagon Project — matched by CVE ID, not by vendor name.