Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-26495


An issue was discovered in Open Design Alliance Drawings SDK before 2024.1. A crafted DWG file can force the SDK to reuse an object that has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code.


Published

2023-04-10T20:15:10.770

Last Modified

2025-02-11T17:15:19.193

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-416
  • Type: Secondary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application opendesign drawings_sdk < 2024.1 Yes

References