Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.opendesign.com/security-advisories |
![]() ![]() |
History
Wed, 04 Dec 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 04 Dec 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution. | |
Title | Out-of-bounds Write vulnerability in ODA SDK versions < 2025.10 | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ODA
Published: 2024-12-04T11:40:22.411Z
Updated: 2024-12-04T21:02:00.422Z
Reserved: 2024-09-16T14:09:36.103Z
Link: CVE-2024-8894

Updated: 2024-12-04T19:18:47.311Z

Status : Received
Published: 2024-12-04T12:15:20.763
Modified: 2024-12-04T12:15:20.763
Link: CVE-2024-8894

No data.