Lucene search

K

3d Security Vulnerabilities

cve
cve

CVE-2021-40160

PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary...

7.8CVSS

7.7AI Score

0.001EPSS

2021-12-23 07:15 PM
39
cve
cve

CVE-2021-42070

When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-12-14 04:15 PM
19
cve
cve

CVE-2021-42069

When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.1AI Score

0.001EPSS

2021-12-14 04:15 PM
29
cve
cve

CVE-2021-42068

When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-12-14 04:15 PM
24
cve
cve

CVE-2021-43208

3D Viewer Remote Code Execution...

7.8CVSS

8.3AI Score

0.038EPSS

2021-11-10 01:19 AM
75
cve
cve

CVE-2021-43209

3D Viewer Remote Code Execution...

7.8CVSS

8.3AI Score

0.017EPSS

2021-11-10 01:19 AM
65
cve
cve

CVE-2021-24732

The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting...

5.4CVSS

5.3AI Score

0.001EPSS

2021-10-18 02:15 PM
21
cve
cve

CVE-2021-24398

The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is.....

7.2CVSS

7.2AI Score

0.001EPSS

2021-09-20 10:15 AM
24
cve
cve

CVE-2021-38174

When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becomes temporarily unavailable to the user until restart of the...

6.5CVSS

6.4AI Score

0.001EPSS

2021-09-14 12:15 PM
18
cve
cve

CVE-2021-38318

The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cover-carousel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...

6.1CVSS

6AI Score

0.001EPSS

2021-09-09 07:15 PM
25
cve
cve

CVE-2021-33680

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailable until the user restarts the...

6.5CVSS

6.6AI Score

0.001EPSS

2021-07-14 12:15 PM
20
4
cve
cve

CVE-2021-33681

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unavailable until the user restarts the...

6.5CVSS

6.5AI Score

0.001EPSS

2021-07-14 12:15 PM
21
4
cve
cve

CVE-2021-27041

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary...

7.8CVSS

7.9AI Score

0.001EPSS

2021-06-25 01:15 PM
40
6
cve
cve

CVE-2021-27040

A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary...

3.3CVSS

4.2AI Score

0.002EPSS

2021-06-25 01:15 PM
48
5
cve
cve

CVE-2021-27042

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary...

7.8CVSS

7.9AI Score

0.002EPSS

2021-06-25 01:15 PM
33
7
cve
cve

CVE-2021-27043

An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the...

7.8CVSS

7.5AI Score

0.001EPSS

2021-06-25 01:15 PM
35
4
cve
cve

CVE-2021-33661

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
14
4
cve
cve

CVE-2021-33660

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FLI file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
18
4
cve
cve

CVE-2021-27638

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
17
4
cve
cve

CVE-2021-27639

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
14
cve
cve

CVE-2021-27642

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
17
cve
cve

CVE-2021-27643

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
19
cve
cve

CVE-2021-27640

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
13
cve
cve

CVE-2021-33659

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
17
4
cve
cve

CVE-2021-27641

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

5.5CVSS

5.4AI Score

0.001EPSS

2021-06-09 02:15 PM
19
cve
cve

CVE-2021-31983

Paint 3D Remote Code Execution...

7.8CVSS

7.7AI Score

0.011EPSS

2021-06-08 11:15 PM
82
6
cve
cve

CVE-2021-31945

Paint 3D Remote Code Execution...

7.8CVSS

7.7AI Score

0.014EPSS

2021-06-08 11:15 PM
96
8
cve
cve

CVE-2021-31944

3D Viewer Information Disclosure...

5CVSS

4.8AI Score

0.001EPSS

2021-06-08 11:15 PM
79
5
cve
cve

CVE-2021-31942

3D Viewer Remote Code Execution...

7.8CVSS

7.7AI Score

0.065EPSS

2021-06-08 11:15 PM
75
5
cve
cve

CVE-2021-31943

3D Viewer Remote Code Execution...

7.8CVSS

7.7AI Score

0.065EPSS

2021-06-08 11:15 PM
55
5
cve
cve

CVE-2021-31946

Paint 3D Remote Code Execution...

7.8CVSS

7.7AI Score

0.053EPSS

2021-06-08 11:15 PM
82
7
cve
cve

CVE-2021-31472

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the...

7.8CVSS

7.8AI Score

0.003EPSS

2021-05-07 09:15 PM
17
4
cve
cve

CVE-2021-31466

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the...

7.8CVSS

7.8AI Score

0.002EPSS

2021-05-07 09:15 PM
13
4
cve
cve

CVE-2021-31468

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the...

7.8CVSS

7.8AI Score

0.002EPSS

2021-05-07 09:15 PM
18
cve
cve

CVE-2021-31469

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

3.3CVSS

3.4AI Score

0.001EPSS

2021-05-07 09:15 PM
15
cve
cve

CVE-2021-31467

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

3.3CVSS

3.4AI Score

0.001EPSS

2021-05-07 09:15 PM
17
cve
cve

CVE-2021-31464

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

3.3CVSS

3.4AI Score

0.001EPSS

2021-05-07 09:15 PM
14
cve
cve

CVE-2021-31462

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

3.3CVSS

3.4AI Score

0.001EPSS

2021-05-07 09:15 PM
13
cve
cve

CVE-2021-31465

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the...

7.8CVSS

7.8AI Score

0.002EPSS

2021-05-07 09:15 PM
14
cve
cve

CVE-2021-31471

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

5.5CVSS

5.2AI Score

0.002EPSS

2021-05-07 09:15 PM
15
cve
cve

CVE-2021-31463

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within...

3.3CVSS

3.4AI Score

0.001EPSS

2021-05-07 09:15 PM
15
cve
cve

CVE-2021-31470

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the...

7.8CVSS

7.8AI Score

0.005EPSS

2021-05-07 09:15 PM
15
cve
cve

CVE-2021-27594

When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-03-22 05:15 PM
20
cve
cve

CVE-2021-27595

When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-03-22 05:15 PM
19
cve
cve

CVE-2021-27593

When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-03-22 05:15 PM
20
cve
cve

CVE-2021-27596

When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-03-22 05:15 PM
19
cve
cve

CVE-2021-27584

When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the...

3.3CVSS

4.2AI Score

0.001EPSS

2021-03-09 03:15 PM
18
cve
cve

CVE-2021-27585

When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the...

7.8CVSS

7.5AI Score

0.001EPSS

2021-03-09 03:15 PM
25
2
cve
cve

CVE-2021-27589

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the...

7.8CVSS

7.5AI Score

0.001EPSS

2021-03-09 03:15 PM
20
4
cve
cve

CVE-2021-27586

When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the...

7.8CVSS

7.5AI Score

0.001EPSS

2021-03-09 03:15 PM
16
4
Total number of security vulnerabilities459