7.5

CVE-2005-4470

Exploit

Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.

Data is provided by the National Vulnerability Database (NVD)
BlenderBlenloader Version <= 2.40_pre
BlenderBlenloader Version2.0
BlenderBlenloader Version2.04
BlenderBlenloader Version2.25
BlenderBlenloader Version2.26
BlenderBlenloader Version2.27
BlenderBlenloader Version2.28
BlenderBlenloader Version2.28a
BlenderBlenloader Version2.28c
BlenderBlenloader Version2.30
BlenderBlenloader Version2.31a
BlenderBlenloader Version2.32
BlenderBlenloader Version2.33
BlenderBlenloader Version2.33a
BlenderBlenloader Version2.34
BlenderBlenloader Version2.35
BlenderBlenloader Version2.37
BlenderBlenloader Version2.37a
BlenderBlenloader Version2.39
BlenderBlenloader Version2.40_alpha
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.97% 0.897
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P