CVE-2021-42704 – Inkscape Out-of-bounds Write
https://notcve.org/view.php?id=CVE-2021-42704
Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. La versión 0.91 de Inkscape es vulnerable a una escritura fuera de límites, lo que puede permitir a un atacante ejecutar código de forma arbitraria • https://www.cisa.gov/uscert/ics/advisories/icsa-22-132-03 https://www.integraxor.com/scada-animation-graphic-editor-extension-inkscape • CWE-787: Out-of-bounds Write •
CVE-2021-42702 – Inkscape Access of Uninitialized Pointer
https://notcve.org/view.php?id=CVE-2021-42702
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information. La versión 0.91 de Inkscape puede acceder a un puntero no inicializado, lo que puede permitir a un atacante tener acceso a información no autorizada • https://www.cisa.gov/uscert/ics/advisories/icsa-22-132-03 https://www.integraxor.com/scada-animation-graphic-editor-extension-inkscape • CWE-824: Access of Uninitialized Pointer •
CVE-2021-42700 – Inkscape Out-of-bounds Read
https://notcve.org/view.php?id=CVE-2021-42700
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information. Inkscape 0.91 es vulnerable a una lectura fuera de límites, que puede permitir a un atacante tener acceso a información no autorizada • https://www.cisa.gov/uscert/ics/advisories/icsa-22-132-03 https://www.integraxor.com/scada-animation-graphic-editor-extension-inkscape • CWE-125: Out-of-bounds Read •
CVE-2012-6076
https://notcve.org/view.php?id=CVE-2012-6076
Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts. Inkscape anterior a v0.48.4 lee ficheros .eps desde /tmp en lugar del directorio actual, permitiendo a usuarios locales obtener información sensible y posiblemente tener otro impacto no especificado. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654341 http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html http://www.openwall.com/lists/oss-security/2012/12/30/2 http://www.ubuntu.com/usn/USN-1712-1 https://bugs.launchpad.net/inkscape/+bug/911146 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-5656
https://notcve.org/view.php?id=CVE-2012-5656
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack. El proceso de rasterización en Inkscape antes de v0.48.4 permite a los usuarios locales leer archivos de su elección a través de entidades externas en un archivo SVG. Se trata de un ataque también conocido como ataque de inyección XML a una entidad externa (XXE). • http://bazaar.launchpad.net/~inkscape.dev/inkscape/trunk/revision/11931 http://lists.fedoraproject.org/pipermail/package-announce/2012-December/095024.html http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095380.html http://lists.fedoraproject.org/pipermail/package-announce/2013-January/095398.html http://lists.opensuse.org/opensuse-updates/2013-02/msg00041.html http://lists.opensuse.org/opensuse-updates/2013-02/msg00043.html http://www.openwall.com/lists/oss-security/2012/12/20 • CWE-611: Improper Restriction of XML External Entity Reference •