Sap 3D Visual Enterprise Viewer vulnerabilities

127 known vulnerabilities affecting sap/3d_visual_enterprise_viewer.

Total CVEs
127
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH45MEDIUM73LOW9

Vulnerabilities

Page 1 of 7
CVE-2022-41211HIGHCVSS 7.8v92022-11-08
CVE-2022-41211 [HIGH] CWE-119 CVE-2022-41211: Due to lack of proper memory management, when a victim opens manipulated file received from untruste Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten space in memory. The accessed memory must be filled wi
nvd
CVE-2022-41194HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41194 [HIGH] CWE-119 CVE-2022-41194: Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript ( Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Postscript (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.
nvd
CVE-2022-41188HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41188 [HIGH] CWE-119 CVE-2022-41188: Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, Obj Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.
nvd
CVE-2022-41201HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41201 [HIGH] CWE-119 CVE-2022-41201: Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary ( Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to ove
nvd
CVE-2022-41190HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41190 [HIGH] CWE-119 CVE-2022-41190: Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTran Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to over
nvd
CVE-2022-41193HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41193 [HIGH] CWE-119 CVE-2022-41193: Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script Due to lack of proper memory management, when a victim opens a manipulated Encapsulated Post Script (.eps, ai.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to ov
nvd
CVE-2022-41199HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41199 [HIGH] CWE-119 CVE-2022-41199: Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwri
nvd
CVE-2022-41200HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41200 [HIGH] CWE-119 CVE-2022-41200: Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic ( Due to lack of proper memory management, when a victim opens a manipulated Scalable Vector Graphic (.svg, svg.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to o
nvd
CVE-2022-41187HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41187 [HIGH] CWE-119 CVE-2022-41187: Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, O Due to lack of proper memory management, when a victim opens a manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers t
nvd
CVE-2022-41189HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41189 [HIGH] CWE-119 CVE-2022-41189: Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTran Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dwg, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to over
nvd
CVE-2022-41195HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41195 [HIGH] CWE-119 CVE-2022-41195: Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Due to lack of proper memory management, when a victim opens a manipulated EAAmiga Interchange File Format (.iff, 2d.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refer
nvd
CVE-2022-41197HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41197 [HIGH] CWE-119 CVE-2022-41197: Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.
nvd
CVE-2022-41196HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41196 [HIGH] CWE-119 CVE-2022-41196: Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten
nvd
CVE-2022-41202HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41202 [HIGH] CWE-119 CVE-2022-41202: Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vd Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to over
nvd
CVE-2022-41191HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41191 [HIGH] CWE-119 CVE-2022-41191: Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to o
nvd
CVE-2022-41186HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41186 [HIGH] CWE-119 CVE-2022-41186: Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile Due to lack of proper memory management, when a victim opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, a Remote Code Execution can be triggered when payload forces a stack-based overflow and or a re-use of dangling pointer which refers to overwritten s
nvd
CVE-2022-41192HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41192 [HIGH] CWE-119 CVE-2022-41192: Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, J Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.
nvd
CVE-2022-41198HIGHCVSS 7.8fixed in 9.02022-10-11
CVE-2022-41198 [HIGH] CWE-119 CVE-2022-41198: Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp. Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten
nvd
CVE-2022-35171MEDIUMCVSS 5.5v92022-07-12
CVE-2022-35171 [MEDIUM] CWE-20 CVE-2022-35171: When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SA When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below
nvd
CVE-2022-32242MEDIUMCVSS 5.5≤ 9.02022-06-14
CVE-2022-32242 [MEDIUM] CWE-20 CVE-2022-32242: When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
nvd