Page 3 of 36 results (0.008 seconds)

CVSS: 8.8EPSS: 3%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de carga de DPX de la suite d... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.hdr' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de carga de RADIANCE de ... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de carga de bmp de la suite d... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de reproducción de animaciones de la suit... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de reproducción de animaciones de la suit... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 7.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog. Existe un desbordamiento de enteros explotable en la funcionalidad de miniaturas de la suite de código abierto de c... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 1

24 Apr 2018 — An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerability. Existe un desbordamiento de enteros explotable en la funcionalidad de carga de imágenes de la suite de códi... • https://lists.debian.org/debian-lts-announce/2018/08/msg00011.html • CWE-190: Integer Overflow or Wraparound •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

27 Apr 2014 — The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103. La rutina de deshacer guardar salir en el kernel en Blender 2.5, 2.63a, y anteriores permite a usuarios locales sobrescribir archivos arbitrarios a través de un ataque symlink sobre el archivo quit.blend temporal. NOTA: este problema podría ser una regresión de CVE-2008-1103. • http://lists.opensuse.org/opensuse-updates/2013-02/msg00047.html • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 6.1EPSS: 0%CPEs: 72EXPL: 3

18 Nov 2013 — Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php. Vulnerabilidad de XSS en el plugin Tweet Blender anterior a la versión 4.0.2 para WordPress permite a atacantes remotos inyectar script web o HTML arbitrario a través del parámetro tb_tab_index a wp-admin/options-general.php. WordPress Tweet Blender plugin version 4.0.1 suffers from a cro... • https://packetstorm.news/files/id/124047 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 4%CPEs: 4EXPL: 2

06 Nov 2009 — Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA. Blender v2.34, v2.35a, v2.40, y v2.49b permite a atacantes remotos ejecutar código de su elección mediante un fichero .blend que contenga sentencias Python en la acción onLoad de un ScriptLink SDNA. Multiple vulnerabilities have been found in Blender, the worst of which could allow attackers to execute arbitrary code. Versions les... • https://www.exploit-db.com/exploits/9843 • CWE-94: Improper Control of Generation of Code ('Code Injection') •