Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.
{
"versions": [
{
"introduced": "2.36.0"
},
{
"last_affected": "9.x"
},
{
"introduced": "0"
},
{
"fixed": "10.0.1"
}
]
}