Skip to main content

Vendor archive

opendesign CVEs

Beta · best-effort

49 CVEs tagged to vendor opendesign1 Critical, 47 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2023-5180

Published Dec 26, 2023

An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5179

Published Nov 7, 2023

An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22670

Published Apr 15, 2023

A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22669

Published Apr 15, 2023

Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length h…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26495

Published Apr 10, 2023

An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28809

Published Jul 17, 2022

An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with an invalid vertex number in a r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28808

Published Jul 17, 2022

An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28807

Published Jul 17, 2022

An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists when rendering a .dwg file after it's opened in the recovery…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44860

Published Dec 21, 2021

An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An un…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44859

Published Dec 21, 2021

An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TGA files. An un…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44423

Published Dec 21, 2021

An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer before 2022.12. The specific issue exists after loading BMP f…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44422

Published Dec 21, 2021

An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before 2022.12. Crafted data in a BMP file can trigger a write op…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44048

Published Dec 5, 2021

An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44047

Published Dec 5, 2021

A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing DWF/DWFX files. C…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44046

Published Dec 5, 2021

An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An unchecked return value of a function (verifying input data fr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44045

Published Dec 5, 2021

An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN fil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44044

Published Dec 5, 2021

An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists with parsing JPG files. Craft…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43582

Published Nov 22, 2021

A Use-After-Free Remote Vulnerability exists when reading a DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DWG fi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43581

Published Nov 22, 2021

An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. The specific issue exists within the parsing of U3D files. In…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 49 CVEsPage 1 of 2