{"id":"CVE-2023-46045","details":"Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.","modified":"2026-08-12T03:51:20.234354855Z","published":"2024-02-02T00:00:00Z","related":["CGA-jjfh-2g79-3r6x","SUSE-SU-2024:1351-1","SUSE-SU-2024:1351-2","openSUSE-SU-2024:13761-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46045.json"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/176816/graphviz-2.43.0-Buffer-Overflow-Code-Execution.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jan/62"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jan/73"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2024/Feb/24"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2024/Jan/73"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/02/01/2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46045.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46045"},{"type":"REPORT","url":"https://gitlab.com/graphviz/graphviz/-/issues/2441"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2024/Feb/24"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/graphviz/graphviz","events":[{"introduced":"0"},{"fixed":"5733d3a95898f1380424ab15f966ace9a283d506"},{"fixed":"1c6cb9d3de553bd3e3caeea9a61ebe04034d07ee"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"2.36.0"},{"fixed":"9.x"},{"introduced":"0"},{"fixed":"10.0.1"}]}}],"versions":["9.0.0","8.1.0","8.0.5","8.0.4","8.0.3","8.0.2","8.0.1","7.0.6","7.0.5","7.0.4","7.0.3","7.0.2","7.0.1","7.0.0","6.0.2","6.0.1","5.0.1","5.0.0","4.0.0","3.0.0","2.50.0","2.49.3","2.49.2","2.49.1","2.49.0","2.48.0","2.47.3","2.47.2","2.47.1","2.47.0","2.46.1","2.46.0","2.44.1","stable_release_2.44.0","2.44.0","stable_release_2.42.4","2.42.4","stable_release_2.42.3","2.42.3","stable_release_2.42.2","2.42.2","stable_release_2.42.0","2.42.0","TRAVIS_CI_BUILD_EXPERIMENTAL","2.38.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46045.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}