VYPR

Libslic3r

by Slic3r

CVEs (8)

  • CVE-2022-36788HigApr 20, 2023
    risk 0.53cvss 8.1epss 0.01

    A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially-crafted STL file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2020-28590MedApr 13, 2021
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj file could lead to information disclosure. An attacker can provide a malicious file to trigger this…

  • CVE-2020-28591MedMar 3, 2021
    risk 0.42cvss 6.5epss 0.02

    An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this…

  • CVE-2021-44962MedMar 1, 2022
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. A specially crafted stl file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-44961MedMar 1, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.

  • CVE-2021-45847MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file.

  • CVE-2021-45846MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a metadata tag lacks a "type" attribute.

  • CVE-2022-38072MedApr 3, 2023
    risk 0.35cvss 6.5epss 0.01

    An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…