<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Blender</title>
  <link>https://cvedaily.com/pages/tags/blender.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/blender.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Blender</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-27779 – Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27779</guid>
    <pubDate>Wed, 19 Mar 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27779</strong></p>
  <p>Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_blender.py` lines 20 and 21. `model_fusion_a` and `model_fusion_b` from voice_blender.py take user-supplied input (e.g. a path to a model) and pass that value to the `run_model_blender_script` and later to `model_blender` function, which loads these two models with `torch.load` in…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47720 – In the Linux kernel, the following vulnerability has been resolved:

drm/amd/dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47720</guid>
    <pubDate>Mon, 21 Oct 2024 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47720</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amd/display: Add null check for set_output_gamma in dcn30_set_output_transfer_func  This commit adds a null check for the set_output_gamma function pointer in the  dcn30_set_output_transfer_func function. Previously, set_output_gamma was being checked for nullity at line 386, but then it was being dereferenced without any nu…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2833 – Endless Infinite loop in Blender-thumnailing due to logical bugs.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2833</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2833</strong></p>
  <p>Endless Infinite loop in Blender-thumnailing due to logical bugs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2832 – A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2832</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2832</strong></p>
  <p>A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-395</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2831 – A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2831</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2831</strong></p>
  <p>A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0546 – A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0546</guid>
    <pubDate>Thu, 24 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0546</strong></p>
  <p>A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0545 – An integer overflow in the processing of loaded 2D images leads to a write-what-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0545</guid>
    <pubDate>Thu, 24 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0545</strong></p>
  <p>An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0544 – An integer underflow in the DDS loader of Blender leads to an out-of-bounds read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0544</guid>
    <pubDate>Thu, 24 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0544</strong></p>
  <p>An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2918 – An exploitable integer overflow exists in the Image loading functionality of the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2918</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2918</strong></p>
  <p>An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerabi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2908 – An exploitable integer overflow exists in the thumbnail functionality of the Ble...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2908</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2908</strong></p>
  <p>An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to render the thumbnail for the file while in the File->Open dialog.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2907 – An exploitable integer overflow exists in the animation playing functionality of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2907</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2907</strong></p>
  <p>An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerabil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2906 – An exploitable integer overflow exists in the animation playing functionality of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2906</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2906</strong></p>
  <p>An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerabil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2905 – An exploitable integer overflow exists in the bmp loading functionality of the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2905</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2905</strong></p>
  <p>An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger thi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2904 – An exploitable integer overflow exists in the RADIANCE loading functionality of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2904</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2904</strong></p>
  <p>An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.hdr' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigge…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2903 – An exploitable integer overflow exists in the DPX loading functionality of the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2903</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2903</strong></p>
  <p>An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger thi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2902 – An exploitable integer overflow exists in the DPX loading functionality of the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2902</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2902</strong></p>
  <p>An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger thi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2901 – An exploitable integer overflow exists in the IRIS loading functionality of the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2901</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2901</strong></p>
  <p>An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.iris' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger t…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2900 – An exploitable integer overflow exists in the PNG loading functionality of the B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2900</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2900</strong></p>
  <p>An exploitable integer overflow exists in the PNG loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.png' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger thi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-2899 – An exploitable integer overflow exists in the TIFF loading functionality of the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2899</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-2899</strong></p>
  <p>An exploitable integer overflow exists in the TIFF loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.tif' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12105 – An exploitable integer overflow exists in the way that the Blender open-source 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12105</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12105</strong></p>
  <p>An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c applies a particular object modifier to a Mesh. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12104 – An exploitable integer overflow exists in the way that the Blender open-source 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12104</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12104</strong></p>
  <p>An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this v…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12103 – An exploitable integer overflow exists in the way that the Blender open-source 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12103</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12103</strong></p>
  <p>An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts text rendered as a font into a curve. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in o…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12102 – An exploitable integer overflow exists in the way that the Blender open-source 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12102</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12102</strong></p>
  <p>An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c converts curves to polygons. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12101 – An exploitable integer overflow exists in the 'modifier_mdef_compact_influences'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12101</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12101</strong></p>
  <p>An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulner…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12100 – An exploitable integer overflow exists in the 'multires_load_old_dm' functionali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12100</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12100</strong></p>
  <p>An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12099 – An exploitable integer overflow exists in the upgrade of the legacy Mesh attribu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12099</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12099</strong></p>
  <p>An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigg…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12086 – An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12086</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12086</strong></p>
  <p>An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12082 – An exploitable integer overflow exists in the 'CustomData' Mesh loading function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12082</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12082</strong></p>
  <p>An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to edit an object within a .blend library i…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12081 – An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12081</guid>
    <pubDate>Tue, 24 Apr 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12081</strong></p>
  <p>An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-5105 – The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-5105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-5105</guid>
    <pubDate>Sun, 27 Apr 2014 20:55:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-5105</strong></p>
  <p>The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file.  NOTE: this issue might be a regression of CVE-2008-1103.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-5105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-6342 – Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6342</guid>
    <pubDate>Fri, 22 Nov 2013 20:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-6342</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3850 – Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3850</guid>
    <pubDate>Fri, 06 Nov 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3850</strong></p>
  <p>Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-4863 – Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4863</guid>
    <pubDate>Sat, 01 Nov 2008 00:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-4863</strong></p>
  <p>Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1103 – Multiple unspecified vulnerabilities in Blender have unknown impact and attack v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1103</guid>
    <pubDate>Mon, 28 Apr 2008 20:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1103</strong></p>
  <p>Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1102 – Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1102</guid>
    <pubDate>Tue, 22 Apr 2008 04:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1102</strong></p>
  <p>Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1253 – Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1253</guid>
    <pubDate>Sat, 03 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1253</strong></p>
  <p>Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4470 – Heap-based buffer overflow in the get_bhead function in readfile.c in Blender Bl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4470</guid>
    <pubDate>Thu, 22 Dec 2005 00:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4470</strong></p>
  <p>Heap-based buffer overflow in the get_bhead function in readfile.c in Blender BlenLoader 2.0 through 2.40pre allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .blend file with a negative bhead.len value, which causes less memory to be allocated than expected, possibly due to an integer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3302 – Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3302</guid>
    <pubDate>Mon, 24 Oct 2005 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3302</strong></p>
  <p>Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3151 – Buffer overflow in blenderplay in Blender Player 2.37a allows attackers to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3151</guid>
    <pubDate>Wed, 05 Oct 2005 22:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3151</strong></p>
  <p>Buffer overflow in blenderplay in Blender Player 2.37a allows attackers to execute arbitrary code via a long command line argument.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3151">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
