Tonybybell maintains GTKWave, a waveform viewer used in digital design and circuit simulation workflows, which despite a narrow product portfolio has achieved significant prominence in the EDA tooling landscape. The vendor's vulnerability footprint concentrates in memory-safety and input-validation weaknesses including integer overflow, buffer boundary violations, out-of-bounds writes, and OS command injection, patterns typical of tools that parse complex binary waveform formats and accept user-supplied simulation data. These weakness classes reflect the parser-oriented attack surface inherent to waveform analysis software, where untrusted data from simulation outputs and external file formats must be safely decoded and rendered. Defenders should prioritize updates to this widely adopted design tool, particularly in environments where GTKWave processes waveforms from untrusted or semi-trusted simulation sources; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tonybybell over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32650HIGH An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can | Jan 8, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-38657HIGH An out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code executi | Jan 8, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-39317HIGH Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-39316HIGH Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-39271HIGH Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code executio | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-38583HIGH A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-36864HIGH An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to ar | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-36747HIGH Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memo | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-36746HIGH Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 fstWritex len functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memo | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-35961HIGH Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A | Jan 8, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tonybybell.
Media articles that mention a CVE ID that affects a product developed by Tonybybell — matched by CVE ID, not by vendor name.