HIGH🇵🇱 Wersja polska

CVE-2021-43276

CVSS 7.8v3.1pub. 2021-11-14upd. 2024-11-21

An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Opendesign Oda Viewer

    APP
    Opendesign
    < 2022.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2021-43272CRITICAL9.8PL ✓same product

RCE w ODA Viewer przez niewłaściwą obsługę błędów przy plikach DWF

CVE-2023-5180HIGH7.8same vendor

An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of se...

CVE-2023-5179HIGH7.8same vendor

An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start o...

CVE-2023-22669HIGH7.8same vendor

Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length ...

CVE-2023-22670HIGH7.8same vendor

A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK bef...