Page 2 of 27 results (0.008 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. Se ha detectado un problema en Open Design Alliance Drawings SDK antes de 2023.3. Se presenta una vulnerabilidad de lectura fuera de límites cuando es leído un archivo DWG con un número de vértices no válido en un modo de recuperación. • https://www.opendesign.com/security-advisories • CWE-306: Missing Authentication for Critical Function •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. Se ha detectado un problema en Open Design Alliance Drawings SDK versiones anteriores a 2023.3. Se presenta una vulnerabilidad de lectura fuera de límites cuando se leen archivos DWG en modo de recuperación. • https://www.opendesign.com/security-advisories • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process. Se ha detectado un problema en Open Design Alliance Drawings SDK anterior a 2023.2. Se presenta una vulnerabilidad de lectura fuera de límites cuando es renderizado un archivo .dwg después de abrirlo en el modo de recuperación. • https://www.opendesign.com/security-advisories • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before 2022.12. Crafted data in a BMP file can trigger a write operation past the end of an allocated buffer, or lead to a heap-based buffer overflow. An attacker can leverage this vulnerability to execute code in the context of the current process. Se presenta una vulnerabilidad de comprobación de entrada inapropiada cuando es leído un archivo BMP usando el SDK de dibujos de Open Design Alliance versiones anteriores a 2022.12. Los datos diseñados en un archivo BMP pueden desencadenar una operación de escritura más allá del final de un búfer asignado, o conllevar a un desbordamiento del búfer en la región heap de la memoria. • https://www.opendesign.com/security-advisories • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An unchecked input data from a crafted TGA file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process. Se presenta una vulnerabilidad de lectura fuera de límites cuando es leído un archivo TGA usando Open Design Alliance Drawings SDK versiones anteriores a 2022.12. • https://www.opendesign.com/security-advisories • CWE-125: Out-of-bounds Read •