Vulnerabilidades em GTKWave

82 resultados
Análise Vexday

GTKWave acumula 82 CVEs catalogadas, volume considerável para uma ferramenta de visualização de formas de onda, com CWE-190 (Integer Overflow or Wraparound) como o tipo de falha mais recorrente — categoria que frequentemente serve de vetor para corrupção de memória e execução de código. Nenhuma das vulnerabilidades consta no catálogo KEV da CISA, o que coloca a taxa de exploração ativa abaixo da média geral do catálogo, e a CVE mais relevante no momento, CVE-2023-35961, apresenta EPSS de 0,0149, indicando probabilidade baixa de exploração observada em campo. A ausência de PoCs públicas conhecidas e de surgimentos recentes nos últimos 90 dias sugere um perfil de risco momentaneamente estável, mas o volume total de falhas e o padrão de CWE merecem atenção de equipes que utilizam GTKWave em ambientes de desenvolvimento ou análise de hardware, especialmente ao processar arquivos não confiáveis.

CVE-2023-37443HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-37420HIGHMultiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2023-37417HIGHMultiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2023-39235HIGHMultiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crEPSS 0.4%CVE-2023-37416HIGHMultiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2023-39443HIGHMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can EPSS 0.4%CVE-2023-37446HIGHMultiple out-of-bounds read vulnerabilities exist in the VCD var definition section functionality of GTKWave 3.3.115. A specially crafted .vEPSS 0.4%CVE-2023-38622HIGHMultiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt fiEPSS 0.4%CVE-2023-35994HIGHMultiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A speciaEPSS 0.4%CVE-2023-39274HIGHMultiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 EPSS 0.4%CVE-2023-36864HIGHAn integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A spEPSS 0.4%CVE-2023-39275HIGHMultiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 EPSS 0.4%CVE-2023-39317HIGHMultiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 filEPSS 0.4%CVE-2023-35969HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. EPSS 0.4%CVE-2023-35957HIGHMultiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A speEPSS 0.4%CVE-2023-39270HIGHMultiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 EPSS 0.4%CVE-2023-39316HIGHMultiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 filEPSS 0.4%CVE-2023-39273HIGHMultiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 EPSS 0.4%CVE-2023-35996HIGHMultiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A speciaEPSS 0.4%CVE-2023-39271HIGHMultiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 EPSS 0.4%