Vulnerabilidades en GTKWave

82 resultados
Análisis Vexday

GTKWave acumula 82 CVEs catalogadas, volume considerável para uma ferramenta de visualização de formas de onda, com CWE-190 (Integer Overflow or Wraparound) como o tipo de falha mais recorrente — categoria que frequentemente serve de vetor para corrupção de memória e execução de código. Nenhuma das vulnerabilidades consta no catálogo KEV da CISA, o que coloca a taxa de exploração ativa abaixo da média geral do catálogo, e a CVE mais relevante no momento, CVE-2023-35961, apresenta EPSS de 0,0149, indicando probabilidade baixa de exploração observada em campo. A ausência de PoCs públicas conhecidas e de surgimentos recentes nos últimos 90 dias sugere um perfil de risco momentaneamente estável, mas o volume total de falhas e o padrão de CWE merecem atenção de equipes que utilizam GTKWave em ambientes de desenvolvimento ou análise de hardware, especialmente ao processar arquivos não confiáveis.

CVE-2023-35961HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35960HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35962HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35964HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35959HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35963HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35956HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35703HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2023-35704HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2023-37419HIGHMultiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2023-37282HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_Read dmem extraction functionality of GTKWave 3.3.115. A specially crafted .vzt EPSS 0.4%CVE-2023-36861HIGHAn out-of-bounds write vulnerability exists in the VZT LZMA_read_varint functionality of GTKWave 3.3.115. A specially crafted .vzt file can EPSS 0.4%CVE-2023-39234HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crEPSS 0.4%CVE-2023-36915HIGHMultiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A sEPSS 0.4%CVE-2023-37445HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-35955HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-35702HIGHMultiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fEPSS 0.4%CVE-2023-35970HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-35958HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-38583HIGHA stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially craftEPSS 0.4%