Fig2dev Project maintains a specialized graphics conversion utility that translates figures and diagrams across multiple formats, a narrowly scoped but durably deployed tool within technical and scientific workflows. The vulnerability footprint concentrates entirely within the single fig2dev product and recurs through memory-safety and arithmetic weakness classes including out-of-bounds writes, classic buffer overflows, NULL-pointer dereferences, divide-by-zero conditions, and double-free errors, reflecting the parser-intensive demands of handling diverse input file formats. These weakness classes are characteristic of native-code graphics processing tools and can arise from the need to handle untrusted and complex binary or textual diagram specifications without strict bounds checking. Defenders should treat fig2dev input processing as a potential vector in environments where the tool processes untrusted figure files; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fig2dev Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16140HIGH A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. | Aug 30, 2018 | 7.8 | 26 | NO | NO |
CVE-2025-46397HIGH A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. | Apr 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-3561HIGH An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application | May 26, 2021 | 7.1 | 24 | NO | NO |
CVE-2020-21676MEDIUM A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file int | Aug 10, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21675MEDIUM A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk for | Aug 10, 2021 | 5.5 | 21 | NO | NO |
CVE-2025-46400MEDIUM In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-46399MEDIUM A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-46398MEDIUM In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-31164MEDIUM heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. | Mar 28, 2025 | 6.6 | 20 | NO | NO |
CVE-2025-31163MEDIUM Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function. | Mar 28, 2025 | 6.6 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fig2dev Project.
Media articles that mention a CVE ID that affects a product developed by Fig2dev Project — matched by CVE ID, not by vendor name.