CVE-2021-40401
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
- EPSS probability
- 0.27%
- CWE
- CWE-252
- Published
- 2022-02-04
- Last modified
- 2026-03-13
Affected products
- n/a Gerbv
Weakness type
Related vulnerabilities
- CVE-2020-6152 — A code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A spe
- CVE-2026-11972 — tarfile opened in streaming mode mishandles EOF
- CVE-2025-66565 — Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
- CVE-2026-22861 — iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22255 — iccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp
- CVE-2026-22047 — iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22046 — iccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2026-21920 — Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash