5.5

CVE-2026-42479

An out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because coordIndex values from parsed input are used as direct array indices without validation against the size of the coordinate array during geometry processing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opencascade ≫ Open Cascade Technology Version <= 7.9.3
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update beta1
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update rc1
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update rc2
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update rc3
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update rc4
Opencascade ≫ Open Cascade Technology Version 8.0.0 Update rc5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://gist.github.com/sgInnora/dfba083d04906283e9c92aea78e2d94a
Third Party Advisory