Svgpp is a specialized SVG parsing and processing library that, despite limited product scope, occupies a structural role in graphics-handling pipelines across applications and embedded systems. Its observed vulnerability profile centers on memory-safety issues endemic to C++ parsing implementations, including out-of-bounds writes, NULL-pointer dereferences, and out-of-bounds reads that arise during malformed SVG document processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Svgpp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6246CRITICAL An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library in Boost, the return code is used as an address, leading to a | Jan 13, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-44960MEDIUM In SVGPP SVG++ library 1.3.0, the XMLDocument::getRoot function in the renderDocument function handled the XMLDocument object improperly, returning a null pointer in advance at the | Feb 15, 2022 | 6.5 | 22 | NO | NO |
CVE-2019-6247HIGH An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the | Jan 13, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-6245HIGH An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit | Jan 13, 2019 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Svgpp.
Media articles that mention a CVE ID that affects a product developed by Svgpp — matched by CVE ID, not by vendor name.