CVE-2014-1236: Graphviz

High severity, CVSS 10.0. EPSS: 6.1% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list."

Affected products

Published 2014-01-10. Last modified 2026-06-17.