Fig2dev
Vendor:
First CVE: Aug 30, 2018 · Active for 7 years
20
Total CVEs
More Total CVEs than 94% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fig2dev over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2018
7 years ago
Most Recent CVE
Apr 23, 2025
458 days ago
CVE Severity & Scoring
Fig2dev20 CVEs
85%
15%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local20 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (35.0%)
Unknown0 (0.0%)
Required13 (65.0%)
Privileges Required
Low7 (35.0%)
High0 (0.0%)
None13 (65.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16140HIGH A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. | Aug 30, 2018 | 7.8 | 26 | NO | NO |
CVE-2025-46397HIGH A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. | Apr 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-3561HIGH An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application | May 26, 2021 | 7.1 | 24 | NO | NO |
CVE-2020-21676MEDIUM A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file int | Aug 10, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21675MEDIUM A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk for | Aug 10, 2021 | 5.5 | 21 | NO | NO |
CVE-2025-46400MEDIUM In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-46399MEDIUM A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-46398MEDIUM In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. | Apr 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-31164MEDIUM heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. | Mar 28, 2025 | 6.6 | 20 | NO | NO |
CVE-2025-31163MEDIUM Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function. | Mar 28, 2025 | 6.6 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Fig2dev
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.9a | 7 | 6.3 | 0.2% | 0 | 0 |
| 3.2.8 | 1 | 7.1 | 1.2% | 0 | 0 |
| 3.2.7b | 9 | 5.5 | 0.9% | 0 | 0 |
| 3.2.7a | 1 | 7.8 | 1.4% | 0 | 0 |