CVE-2022-33034: LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
CVE-2022-35164 (https://github.com/LibreDWG/libredwg/issues/497): LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain. Looks like there's a patch on a separate branch.
CVE-2022-45332 (https://github.com/LibreDWG/libredwg/issues/524): LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.