CVE-2016-9304
published 2017-01-25CVE-2016-9304: Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.85%
76.7th percentile
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | fbx_software_development_kit | <= 2017.0 | — |
| virustotal | yara | >= 0 < 3.4.0+dfsg-2ubuntu0.1~esm1 | 3.4.0+dfsg-2ubuntu0.1~esm1 |
| virustotal | yara | >= 0 < 3.7.1-1ubuntu2+esm1 | 3.7.1-1ubuntu2+esm1 |
| virustotal | yara | >= 0 < 3.9.0-1ubuntu0.1~esm1 | 3.9.0-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
yara vulnerabilities
osv·2026-03-09·CVSS 7.5
CVE-2016-10211 yara vulnerabilities
yara vulnerabilities
Kamil Frankowicz discovered that a number of YARA's functions
generated memory exceptions when processing specially crafted
rules or files. A remote attacker could possibly use these
issues to cause YARA to crash, resulting in a denial of
service. These issues only affected Ubuntu 16.04 LTS.
(CVE-2016-10211, CVE-2017-5923, CVE-2017-5924, CVE-2017-8294,
CVE-2017-8929, CVE-2017-9304, CVE-2017-9438, CVE-2017-9465)
Jurriaan Bremer discovered that YARA's yr_object_array_set_limit()
function could result in a heap buffer overflow when scanning
specially crafted .NET files. A remote attacker could possibly use
this issue to cause YARA to crash, resulting in a denial of service.
This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11328)
It was discovered that YARA's yr_exe
GHSA
GHSA-5559-hrwm-fcx5: Multiple buffer overflows in the Autodesk FBX-SDK before 2017
ghsa_unreviewed·2022-05-17
CVE-2016-9304 [HIGH] CWE-119 GHSA-5559-hrwm-fcx5: Multiple buffer overflows in the Autodesk FBX-SDK before 2017
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-25
Published