9.3

CVE-2011-2478

Google SketchUp before 8 does not properly handle edge geometry in SketchUp (aka .SKP) files, which allows remote attackers to execute arbitrary code via a crafted file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Sketchup Update maintenance_2 Version <= 7.1
Google ≫ Sketchup Version 6.0 Update maintenance_6
Google ≫ Sketchup Version 7.0 Update maintenance_1
Google ≫ Sketchup Version 7.1
Google ≫ Sketchup Version 7.1 Update maintenance_1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.15% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://support.google.com/sketchup/bin/static.py?hl=en&page=release_notes.cs&rd=1
http://technet.microsoft.com/en-us/security/msvr/msvr11-006