CVE-2021-43276

HIGH

Open Design Alliance ODA Viewer <2022.8 - Memory Corruption

Title source: llm
STIX 2.1

Description

An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.opendesign.com/security-advisories

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 58.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (1)
opendesign/oda_viewer < 2022.8
Published Nov 14, 2021
Tracked Since Feb 18, 2026