CVE-2018-17333: LIBSVG2 Project LIBSVG2
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because sscanf is misused.
Affected products
- LIBSVG2 Project LIBSVG2: up to and including 2012-10-19
Published 2018-09-22. Last modified 2026-06-17.