VDB

CVE-2025-46400

CVE-2025-46400 PUBLISHED CVSS 5.5 MEDIUM

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.

EPSS 0.10% · 27.5th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.10%
27.5th percentile

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 7
redhatenterprise_linux9.0, 6.0, 7.0
0
fig2dev_projectfig2dev3.2.9a
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 6

Timeline

  • Apr 23, 2025 CVE Published
  • Apr 24, 2025 EPSS Score
  • Apr 24, 2025 PoC Published
  • May 20, 2025 EPSS Score
  • May 31, 2025 EPSS Score
  • Jun 12, 2025 EPSS Score
  • Jun 23, 2025 EPSS Score
  • Jul 5, 2025 EPSS Score
  • Jul 17, 2025 EPSS Score
  • Jul 28, 2025 EPSS Score
  • Aug 9, 2025 EPSS Score
  • Aug 21, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›