Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5202

Опубликовано: 26 мая 2025
Источник: nvd
CVSS3: 3.3
CVSS3: 7.8
CVSS2: 1.7
EPSS Низкий

Описание

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:*
Версия до 5.4.3 (исключая)

EPSS

Процентиль: 4%
0.00022
Низкий

3.3 Low

CVSS3

7.8 High

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-119
CWE-125

Связанные уязвимости

CVSS3: 3.3
ubuntu
23 дня назад

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

CVSS3: 3.3
redhat
24 дня назад

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

CVSS3: 3.3
debian
23 дня назад

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. I ...

CVSS3: 3.3
github
23 дня назад

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.

EPSS

Процентиль: 4%
0.00022
Низкий

3.3 Low

CVSS3

7.8 High

CVSS3

1.7 Low

CVSS2

Дефекты

CWE-119
CWE-125