GnuplotCVEs & Vulnerabilities

15 CVEs affecting Gnuplot products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

gnuplot 15
CVE-2025-31177MEDIUM

gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

8 May 2025
5.5
CVSS
CVE-2025-31181MEDIUM

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

27 Mar 2025
6.2
CVSS
CVE-2025-31180MEDIUM

A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

27 Mar 2025
6.2
CVSS
CVE-2025-31179MEDIUM

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

27 Mar 2025
6.2
CVSS
CVE-2025-31178MEDIUM

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

27 Mar 2025
6.2
CVSS
CVE-2025-31176MEDIUM

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

27 Mar 2025
6.2
CVSS
CVE-2020-25969CRITICAL

gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().

5 Jul 2023
9.8
CVSS
CVE-2021-44917MEDIUM

A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.

21 Dec 2021
5.5
CVSS
CVE-2020-25412CRITICAL

com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.

16 Sep 2020
9.8
CVSS
CVE-2020-25559HIGH

gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.

16 Sep 2020
7.8
CVSS
CVE-2018-19492HIGH

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

23 Nov 2018
7.8
CVSS
CVE-2018-19491HIGH

An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.

23 Nov 2018
7.8
CVSS
CVE-2018-19490HIGH

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

23 Nov 2018
7.8
CVSS
CVE-2017-9670HIGH

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

15 Jun 2017
7.8
CVSS
CVE-2002-2259HIGH

Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.

31 Dec 2002
7.2
CVSS
← PrevPage 1 / 1Next →