Xfig is a lightweight vector graphics editor and the accompanying fig2dev translator utility, both modestly represented in the vulnerability landscape but prominent enough to warrant regular tracking by defenders maintaining legacy Unix and Linux workstations. The recurring vulnerability pattern centers on memory-safety weaknesses—out-of-bounds writes, classic buffer overflows, NULL pointer dereferences, and improper array indexing—that reflect the tools' native C implementation and their role parsing untrusted figure file formats. A meaningful share of the vendor's disclosures reach serious severity; defenders should prioritize patches for systems where these tools process untrusted input files, particularly in shared or research environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xfig Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4227MEDIUM Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3 | Dec 8, 2009 | 6.8 | 34 | NO | YES |
CVE-2021-40241CRITICAL xfig 3.2.7 is vulnerable to Buffer Overflow. | Oct 31, 2022 | 9.8 | 32 | NO | NO |
CVE-2017-16899HIGH An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig form | Nov 20, 2017 | 7.1 | 23 | NO | NO |
CVE-2010-4262MEDIUM Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted | Dec 17, 2010 | 6.8 | 23 | NO | NO |
CVE-2021-32280MEDIUM An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to caus | Sep 20, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21535MEDIUM fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c. | Sep 16, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21532MEDIUM fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c. | Sep 16, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21529MEDIUM fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. | Sep 16, 2021 | 5.5 | 21 | NO | NO |
CVE-2020-21534MEDIUM fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c. | Sep 16, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-21530MEDIUM fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c. | Sep 16, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xfig Project.
Media articles that mention a CVE ID that affects a product developed by Xfig Project — matched by CVE ID, not by vendor name.