CVE-2024-8894
Out-of-bounds Write vulnerability in ODA SDK versions < 2025.10
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
04 dez 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data can trigger an unhandled exception. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:H
Produtos afetados
Open Design Alliance · ODA Drawings SDK - All Versions < 2025.10Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →