Lucene search

K

3d Security Vulnerabilities

cve
cve

CVE-2023-25863

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the...

7.8CVSS

7.5AI Score

0.001EPSS

2023-03-27 09:15 PM
28
cve
cve

CVE-2023-25864

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious...

7.8CVSS

7.7AI Score

0.002EPSS

2023-03-27 09:15 PM
25
cve
cve

CVE-2023-25865

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious...

7.8CVSS

7.7AI Score

0.001EPSS

2023-03-27 09:15 PM
29
cve
cve

CVE-2023-25868

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious...

7.8CVSS

7.7AI Score

0.002EPSS

2023-03-27 09:15 PM
26
cve
cve

CVE-2023-25875

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in...

5.5CVSS

4.9AI Score

0.001EPSS

2023-03-27 09:15 PM
27
cve
cve

CVE-2023-25876

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in...

5.5CVSS

4.9AI Score

0.001EPSS

2023-03-27 09:15 PM
22
cve
cve

CVE-2023-25873

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the...

7.8CVSS

7.5AI Score

0.001EPSS

2023-03-27 09:15 PM
24
cve
cve

CVE-2023-23378

Print 3D Remote Code Execution...

7.8CVSS

7.8AI Score

0.001EPSS

2023-02-14 08:15 PM
79
cve
cve

CVE-2023-23390

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.001EPSS

2023-02-14 08:15 PM
60
cve
cve

CVE-2023-23377

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.001EPSS

2023-02-14 08:15 PM
69
cve
cve

CVE-2022-4453

The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like...

5.4CVSS

5.3AI Score

0.001EPSS

2023-01-16 04:15 PM
31
cve
cve

CVE-2023-21784

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
58
cve
cve

CVE-2023-21788

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
69
cve
cve

CVE-2023-21787

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
64
cve
cve

CVE-2023-21792

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
55
cve
cve

CVE-2023-21786

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
60
cve
cve

CVE-2023-21789

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
66
cve
cve

CVE-2023-21793

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
61
cve
cve

CVE-2023-21791

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
55
cve
cve

CVE-2023-21790

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
62
cve
cve

CVE-2023-21785

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
60
cve
cve

CVE-2023-21780

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
63
cve
cve

CVE-2023-21783

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
56
cve
cve

CVE-2023-21782

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
61
cve
cve

CVE-2023-21781

3D Builder Remote Code Execution...

7.8CVSS

7.8AI Score

0.002EPSS

2023-01-10 10:15 PM
58
cve
cve

CVE-2022-41211

Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten....

7.8CVSS

7.8AI Score

0.001EPSS

2022-11-08 10:15 PM
31
6
cve
cve

CVE-2022-42943

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-21 04:15 PM
29
4
cve
cve

CVE-2022-42944

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-21 04:15 PM
22
4
cve
cve

CVE-2022-42937

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
26
2
cve
cve

CVE-2022-42939

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.9AI Score

0.001EPSS

2022-10-21 04:15 PM
29
4
cve
cve

CVE-2022-42941

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-21 04:15 PM
30
4
cve
cve

CVE-2022-41310

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
23
2
cve
cve

CVE-2022-42938

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.9AI Score

0.001EPSS

2022-10-21 04:15 PM
21
4
cve
cve

CVE-2022-41309

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
29
2
cve
cve

CVE-2022-42935

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
27
2
cve
cve

CVE-2022-42936

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
29
2
cve
cve

CVE-2022-42940

A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.9AI Score

0.001EPSS

2022-10-21 04:15 PM
26
4
cve
cve

CVE-2022-42942

A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

7.8AI Score

0.001EPSS

2022-10-21 04:15 PM
25
4
cve
cve

CVE-2022-42933

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
25
4
cve
cve

CVE-2022-42934

A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current...

7.8CVSS

8AI Score

0.001EPSS

2022-10-21 04:15 PM
25
2
cve
cve

CVE-2022-41200

Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic (.svg, svg.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based...

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
25
cve
cve

CVE-2022-41202

Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based...

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
21
cve
cve

CVE-2022-41201

Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based...

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
26
cve
cve

CVE-2022-41197

Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of.....

7.8CVSS

7.5AI Score

0.001EPSS

2022-10-11 09:15 PM
31
cve
cve

CVE-2022-41199

Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow....

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
27
2
cve
cve

CVE-2022-41198

Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a....

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
29
2
cve
cve

CVE-2022-41195

Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a...

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
24
2
cve
cve

CVE-2022-41196

Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a.....

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
28
2
cve
cve

CVE-2022-41194

Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until...

7.8CVSS

7.5AI Score

0.001EPSS

2022-10-11 09:15 PM
32
4
cve
cve

CVE-2022-41193

Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based...

7.8CVSS

7.9AI Score

0.002EPSS

2022-10-11 09:15 PM
25
4
Total number of security vulnerabilities459