cbcvebase.

Debian Blender vulnerabilities

32 known vulnerabilities affecting debian/blender.

Total CVEs
32
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH24MEDIUM5LOW3

Vulnerabilities

Page 2 of 2
CVE-2017-2906P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2906 [HIGH] CVE-2017-2906: blender - An exploitable integer overflow exists in the animation playing functionality of... An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in ord
debian
CVE-2017-12102P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12102 [HIGH] CVE-2017-12102: blender - An exploitable integer overflow exists in the way that the Blender open-source 3... An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts curves to polygons. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a
debian
CVE-2017-2899P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2899 [HIGH] CVE-2017-2899: blender - An exploitable integer overflow exists in the TIFF loading functionality of the ... An exploitable integer overflow exists in the TIFF loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.tif' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the seq
debian
CVE-2017-12105P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-12105 [HIGH] CVE-2017-12105: blender - An exploitable integer overflow exists in the way that the Blender open-source 3... An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c applies a particular object modifier to a Mesh. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file o
debian
CVE-2022-0546P3HIGHCVSS 7.8fixed in blender 3.1.2+dfsg-1 (bookworm)2022
CVE-2022-0546 [HIGH] CVE-2022-0546: blender - A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads ... A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution. Scope: local bookworm: resolved (fixed in 3.1.2+dfsg-1) bullseye: resolved (fixed in 2.83.5+dfsg-5+deb11u1) sid: resolved (fixed in 3.1.2+dfsg-1) trixie: resolved
debian
CVE-2017-2908P3HIGHCVSS 7.8fixed in blender 2.79.a+dfsg0-1 (bookworm)2017
CVE-2017-2908 [HIGH] CVE-2017-2908: blender - An exploitable integer overflow exists in the thumbnail functionality of the Ble... An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while
debian
CVE-2022-2833P4LOWCVSS 7.5fixed in blender 3.2.2+dfsg-1 (bookworm)2022
CVE-2022-2833 [HIGH] CVE-2022-2833: blender - Endless Infinite loop in Blender-thumnailing due to logical bugs. Endless Infinite loop in Blender-thumnailing due to logical bugs. Scope: local bookworm: resolved (fixed in 3.2.2+dfsg-1) bullseye: open sid: resolved (fixed in 3.2.2+dfsg-1) trixie: resolved (fixed in 3.2.2+dfsg-1)
debian
CVE-2005-4470P4MEDIUMCVSS 7.5fixed in blender 2.40-1 (bookworm)2005
CVE-2005-4470 [HIGH] CVE-2005-4470: blender - Heap-based buffer overflow in the get_bhead function in readfile.c in Blender Bl... Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow. Scope: l
debian
CVE-2008-1102P4MEDIUMCVSS 6.8fixed in blender 2.45-5 (bookworm)2008
CVE-2008-1102 [MEDIUM] CVE-2008-1102: blender - Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows u... Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image. Scope: local bookworm: resolved (fixed in 2.45-5) bullseye: resolved (fixed in 2.45-5) sid: resolved (fixed in 2.45-5) trixie: resolved (fixed in 2.45-5)
debian
CVE-2022-0544P4MEDIUMCVSS 5.5fixed in blender 3.1.2+dfsg-1 (bookworm)2022
CVE-2022-0544 [MEDIUM] CVE-2022-0544: blender - An integer underflow in the DDS loader of Blender leads to an out-of-bounds read... An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1. Scope: local bookworm: resolved (fixed in 3.1.2+dfsg-1) bullseye: resolved (fixed in 2.83.5+dfsg-5+deb11u1) sid: resolved (fixed in
debian
CVE-2008-4863P4LOWCVSS 6.9fixed in blender 2.46+dfsg-5 (bookworm)2008
CVE-2008-4863 [MEDIUM] CVE-2008-4863: blender - Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows loca... Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function. Scope: local bookworm: resolved (fixed in 2.46+dfsg-5) bullseye: resolved (fixed in 2.46+dfsg-5) sid: resolved (fi
debian
CVE-2008-1103P4LOWCVSS 6.9fixed in blender 2.40-1 (bookworm)2008
CVE-2008-1103 [MEDIUM] CVE-2008-1103: blender - Multiple unspecified vulnerabilities in Blender have unknown impact and attack v... Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues." Scope: local bookworm: resolved (fixed in 2.40-1) bullseye: resolved (fixed in 2.40-1) sid: resolved (fixed in 2.40-1) trixie: resolved (fixed in 2.40-1)
debian
Debian Blender vulnerabilities | cvebase