Graphviz is a widely used open-source graph visualization toolkit deployed across documentation systems, network analysis tools, and data-processing pipelines, making it a broadly represented component in technical infrastructure despite its narrow product focus. Its vulnerability profile centers on memory-safety issues—including buffer overflows, out-of-bounds reads, NULL-pointer dereferences, and improper bounds checking—that arise from the parser and rendering complexity of the graph description language and the C-based implementation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphviz over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11023HIGH The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv. | Apr 8, 2019 | 8.8 | 31 | NO | NO |
CVE-2014-1236HIGH Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed | Jan 10, 2014 | 10.0 | 27 | NO | NO |
CVE-2020-18032HIGH Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (applicatio | Apr 29, 2021 | 7.8 | 25 | NO | NO |
CVE-2014-0978HIGH Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file. | Jan 10, 2014 | 9.3 | 24 | NO | NO |
CVE-2008-4555HIGH Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to c | Oct 14, 2008 | 8.5 | 23 | NO | NO |
CVE-2023-46045HIGH Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root. | Feb 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2014-1235HIGH Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a cr | Aug 7, 2017 | 7.8 | 21 | NO | NO |
CVE-2014-9157HIGH Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vect | Dec 3, 2014 | 7.5 | 21 | NO | NO |
CVE-2019-9904MEDIUM An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, relate | Mar 21, 2019 | 6.5 | 19 | NO | NO |
CVE-2018-10196MEDIUM NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of ser | May 30, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphviz.
Media articles that mention a CVE ID that affects a product developed by Graphviz — matched by CVE ID, not by vendor name.