Opendesign Drawings Sdk vulnerabilities
27 known vulnerabilities affecting opendesign/drawings_sdk.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH26LOW1
Vulnerabilities
Page 2 of 2
CVE-2018-18223P4HIGHCVSS 8.1v20192018-10-19
CVE-2018-18223 [HIGH] CVE-2018-18223: Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed fi
Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.
nvd
CVE-2021-31784P4HIGHCVSS 7.8fixed in 2021.62021-04-26
CVE-2021-31784 [HIGH] CWE-787 CVE-2021-31784: An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Dr
An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA platforms in static configuration. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.
nvd
CVE-2023-5179P4HIGHCVSS 7.8fixed in 2024.102023-11-07
CVE-2023-5179 [HIGH] CWE-125 CVE-2023-5179: An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for t
An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
nvd
CVE-2021-32950P4HIGHCVSS 7.1fixed in 2022.4vAll versions prior to 2022.42021-06-17
CVE-2021-32950 [HIGH] CWE-125 CVE-2021-32950: An out-of-bounds read issue exists within the parsing of DXF files in the Drawings SDK (All versions
An out-of-bounds read issue exists within the parsing of DXF files in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a denial-of-service condition or read sensitive information from memory loc
nvd
CVE-2021-32940P4HIGHCVSS 7.1fixed in 2022.5vAll versions prior to 2022.42021-06-17
CVE-2021-32940 [HIGH] CWE-125 CVE-2021-32940: An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All ver
An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All versions prior to 2022.5) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or read sensitive information from memory
nvd
CVE-2021-32938P4HIGHCVSS 7.1fixed in 2022.4vAll versions prior to 2022.42021-06-17
CVE-2021-32938 [HIGH] CWE-125 CVE-2021-32938: Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing o
Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing of DWG files resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a denial-of service condition or read sensitive information from memory.
nvd
CVE-2021-43273P4LOWCVSS 3.3fixed in 2022.112021-11-14
CVE-2021-43273 [LOW] CWE-125 CVE-2021-43273: An Out-of-bounds Read vulnerability exists in the DGN file reading procedure in Open Design Alliance
An Out-of-bounds Read vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.11. Crafted data in a DGN file and lack of verification of input data can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
nvd
← Previous2 / 2