CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:H/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
Percentile
50.7%
An integer underflow in the DDS loader of Blender leads to an out-of-bounds
read, possibly allowing an attacker to read sensitive data using a crafted
DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8
and 3.1.
developer.blender.org/rB0ac83d05d7cccec436bb939e0aa768f6a3d77d72
developer.blender.org/rBbbad834f1c2a1f7030ed9741c486b23241e8885e
developer.blender.org/rBd9dd8c287f57716a827483973c31bbb2face2816
launchpad.net/bugs/cve/CVE-2022-0544
nvd.nist.gov/vuln/detail/CVE-2022-0544
security-tracker.debian.org/tracker/CVE-2022-0544
www.cve.org/CVERecord?id=CVE-2022-0544
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:H/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
Percentile
50.7%