AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-16899

HIGH · CVSS 7.1 EPSS 1.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-11-20 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-16899
Severity
HIGH
CVSS
7.1
EPSS
1.35%

Original NVD Description

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.