Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-38072 | 2 Admesh Project, Slic3r | 2 Admesh, Libslic3r | 2023-04-09 | N/A | 8.8 HIGH |
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |||||
CVE-2018-25033 | 2 Admesh Project, Debian | 2 Admesh, Debian Linux | 2022-10-06 | 5.8 MEDIUM | 8.1 HIGH |
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a. |