Debian Blender vulnerabilities
32 known vulnerabilities affecting debian/blender.
Total CVEs
32
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH24MEDIUM5LOW3
Vulnerabilities
Page 1 of 2
CVE-2005-3302P3MEDIUMCVSS 7.3PoCfixed in blender 2.37a-1 (bookworm)2005
CVE-2005-3302 [HIGH] CVE-2005-3302: blender - Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers t...
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
Scope: local
bookworm: resolved (fixed in 2.37a-1)
bullseye: resolved (fixed in 2.37a-1)
sid: resolved (fixed in 2.37a-1)
trixie: resolved (fixed in 2.37a-1)
debian
CVE-2007-1253P3MEDIUMCVSS 9.3fixed in blender 2.42a-6 (bookworm)2007
CVE-2007-1253 [CRITICAL] CVE-2007-1253: blender - Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender...
Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.
Scope: local
bookworm: resolved (fixed in 2.42a-6)
bullseye: resolved (fixed in 2.42a-6)
sid: resolved (fixed in 2.42a-6)
debian
CVE-2017-2918P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2918 [HIGH] CVE-2017-2918: blender - An exploitable integer overflow exists in the Image loading functionality of the...
An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in or
debian
CVE-2017-12086P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12086 [HIGH] CVE-2017-12086: blender - An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' f...
An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order
debian
CVE-2017-12101P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12101 [HIGH] CVE-2017-12101: blender - An exploitable integer overflow exists in the 'modifier_mdef_compact_influences'...
An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file
debian
CVE-2017-12100P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12100 [HIGH] CVE-2017-12100: blender - An exploitable integer overflow exists in the 'multires_load_old_dm' functionali...
An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to
debian
CVE-2022-0545P3HIGHCVSS 7.8fixed in blender 3.1.2+dfsg-1 (bookworm)2022
CVE-2022-0545 [HIGH] CVE-2022-0545: blender - An integer overflow in the processing of loaded 2D images leads to a write-what-...
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1
debian
CVE-2022-2831P3HIGHCVSS 7.5fixed in blender 3.2.2+dfsg-1 (bookworm)2022
CVE-2022-2831 [HIGH] CVE-2022-2831: blender - A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendt...
A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.
Scope: local
bookworm: resolved (fixed in 3.2.2+dfsg-1)
bullseye: open
sid: resolved (fixed in 3.2.2+dfsg-1)
trixie: resolved (fixed in 3.2.2+dfsg-1)
debian
CVE-2017-12099P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12099 [HIGH] CVE-2017-12099: blender - An exploitable integer overflow exists in the upgrade of the legacy Mesh attribu...
An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it
debian
CVE-2017-12081P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12081 [HIGH] CVE-2017-12081: blender - An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute...
An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a libr
debian
CVE-2017-12082P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12082 [HIGH] CVE-2017-12082: blender - An exploitable integer overflow exists in the 'CustomData' Mesh loading function...
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an o
debian
CVE-2017-2903P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2903 [HIGH] CVE-2017-2903: blender - An exploitable integer overflow exists in the DPX loading functionality of the B...
An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequ
debian
CVE-2017-2907P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2907 [HIGH] CVE-2017-2907: blender - An exploitable integer overflow exists in the animation playing functionality of...
An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in ord
debian
CVE-2017-2902P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2902 [HIGH] CVE-2017-2902: blender - An exploitable integer overflow exists in the DPX loading functionality of the B...
An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequ
debian
CVE-2017-2900P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2900 [HIGH] CVE-2017-2900: blender - An exploitable integer overflow exists in the PNG loading functionality of the B...
An exploitable integer overflow exists in the PNG loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.png' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequ
debian
CVE-2017-2901P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2901 [HIGH] CVE-2017-2901: blender - An exploitable integer overflow exists in the IRIS loading functionality of the ...
An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.iris' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the se
debian
CVE-2017-2905P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2905 [HIGH] CVE-2017-2905: blender - An exploitable integer overflow exists in the bmp loading functionality of the B...
An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequ
debian
CVE-2017-2904P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2904 [HIGH] CVE-2017-2904: blender - An exploitable integer overflow exists in the RADIANCE loading functionality of ...
An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.hdr' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the
debian
CVE-2017-12103P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12103 [HIGH] CVE-2017-12103: blender - An exploitable integer overflow exists in the way that the Blender open-source 3...
An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts text rendered as a font into a curve. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or
debian
CVE-2017-12104P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12104 [HIGH] CVE-2017-12104: blender - An exploitable integer overflow exists in the way that the Blender open-source 3...
An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a lib
debian
1 / 2Next →