cbcvebase.
CVE-2005-4470
published 2005-12-22

CVE-2005-4470: Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of…

PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.79%
92.3th percentile
Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.

Affected

24 ranges
VendorProductVersion rangeFixed in
blenderblender>= 0 < 2.40-12.40-1
blenderblender>= 0 < 2.40-12.40-1
blenderblender>= 0 < 2.40-12.40-1
blenderblenloader<= 2.40_pre
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
blenderblenloader
debianblender< blender 2.40-1 (bookworm)blender 2.40-1 (bookworm)

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.