Libsvg2 is a focused SVG-rendering library with a narrow product scope but significant exposure across applications that parse and display vector graphics. The durable signal centers on memory-safety and resource-management weaknesses, particularly out-of-bounds writes and resource leaks that recur in the library's parsing and rendering code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libsvg2 Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17334CRITICAL An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial o | Sep 22, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17333CRITICAL An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (appli | Sep 22, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17332HIGH An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in certain circumstances, which might result in a | Sep 22, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libsvg2 Project.
Media articles that mention a CVE ID that affects a product developed by Libsvg2 Project — matched by CVE ID, not by vendor name.