Libopencad Project maintains a specialized library for parsing and manipulating CAD file formats, a narrowly scoped but technically complex component that handles untrusted binary input from user-created drawings. The vendor's observed vulnerability signal centers on out-of-bounds read conditions, reflecting the parsing challenges inherent to handling variable-length CAD structures and memory layout assumptions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libopencad Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18481MEDIUM A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an application crash. | Oct 18, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-18480MEDIUM A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadMCHAR function in lib/dwg/io.cpp, resulting in an application crash. | Oct 18, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libopencad Project.
Media articles that mention a CVE ID that affects a product developed by Libopencad Project — matched by CVE ID, not by vendor name.