Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-48423

Disclosure Date: October 24, 2024 (last updated November 06, 2024)
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.
Attacker Value
Unknown

CVE-2024-40724

Disclosure Date: July 19, 2024 (last updated August 08, 2024)
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into the product.
Attacker Value
Unknown

CVE-2022-45748

Disclosure Date: January 20, 2023 (last updated February 24, 2025)
An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp.
Attacker Value
Unknown

CVE-2022-38528

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component Assimp::XFileImporter::CreateMeshes.
Attacker Value
Unknown

CVE-2021-45948

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).
Attacker Value
Unknown

CVE-2014-7726

Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Golosinas Simpson1 (aka com.wGolosinasSimpson1) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0