VDB
CVE-2025-31164
CVE-2025-31164
PUBLISHED
CVSS 6.599999904632568 MEDIUM
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline.
EPSS 0.09% · 25.5th percentile
Risk Scores
CVSS 3.1
6.599999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
EPSS Score
0.09%
25.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fig2dev_project | fig2dev | 3.2.9a |
| xfig | fig2dev | * |
Exploit Intelligence
- https://sourceforge.net/p/mcj/tickets/184/ (nist-nvd)
- CIRCL seen: CVE-2025-31164 (circl-sighting)
- https://lists.debian.org/debian-lts-announce/2025/04/msg00030.html (circl)
Timeline
- Mar 28, 2025 CVE Published
- Mar 29, 2025 EPSS Score
- Apr 11, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 7, 2025 EPSS Score
- May 13, 2025 PoC Published
- May 20, 2025 EPSS Score
- Jun 2, 2025 EPSS Score
- Jun 15, 2025 EPSS Score
- Jun 28, 2025 EPSS Score
- Jul 11, 2025 EPSS Score
- Jul 24, 2025 EPSS Score