ZeroHour

CVE-2022-23095

CVSS 3.1
7.8 high
EPSS
1%p64
Published
()
Modified
Description

Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

Vendors
opendesign
Products
drawings software development kit
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.