CVE-2018-17333: LIBSVG2 Project LIBSVG2

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because sscanf is misused.

Affected products

Published 2018-09-22. Last modified 2026-06-17.