rpm package
opensuse/assimp&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/assimp&distro=openSUSE%20Leap%2016.0
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-10232 | Med | 5.3 | < 5.4.3-160000.4.1 | 5.4.3-160000.4.1 | Jun 1, 2026 | A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit h | |
| CVE-2026-10200 | Med | 5.3 | < 5.4.3-160000.4.1 | 5.4.3-160000.4.1 | May 31, 2026 | A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. Th | |
| CVE-2026-10199 | Low | 3.3 | < 5.4.3-160000.4.1 | 5.4.3-160000.4.1 | May 31, 2026 | A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been d | |
| CVE-2026-10197 | Low | 3.3 | < 5.4.3-160000.4.1 | 5.4.3-160000.4.1 | May 31, 2026 | A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possi | |
| CVE-2025-11277 | Med | 5.3 | < 5.4.3-160000.4.1 | 5.4.3-160000.4.1 | Oct 5, 2025 | A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched loc |
- affected < 5.4.3-160000.4.1fixed 5.4.3-160000.4.1
A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit h
- affected < 5.4.3-160000.4.1fixed 5.4.3-160000.4.1
A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. Th
- affected < 5.4.3-160000.4.1fixed 5.4.3-160000.4.1
A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been d
- affected < 5.4.3-160000.4.1fixed 5.4.3-160000.4.1
A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possi
- affected < 5.4.3-160000.4.1fixed 5.4.3-160000.4.1
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched loc