VDB

CVE-2024-45679

CVE-2024-45679 PUBLISHED CVSS 8.399999618530273 HIGH

PlyLoader.cpp of Assimp provided by Open Asset Import Library contains a heap-based buffer overflow vulnerability (CWE-122). Yuhei Kawakoya of NTT Security Holdings reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

EPSS 0.27% · 19.3th percentile

Risk Scores

CVSS 3.0
8.399999618530273
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.27%
19.3th percentile

Affected Products

VendorProductVersions
Open Asset Import LibraryAssimp

Timeline

  • Sep 18, 2024 CVE Published
  • Sep 18, 2024 EPSS Score
  • Sep 18, 2024 PoC Published
  • Oct 5, 2024 Coalition ESS Score
  • Oct 8, 2024 EPSS Score
  • Oct 24, 2024 Coalition ESS Score
  • Oct 25, 2024 Coalition ESS Score
  • Oct 27, 2024 EPSS Score
  • Nov 6, 2024 Coalition ESS Score
  • Nov 16, 2024 EPSS Score
  • Dec 7, 2024 EPSS Score
  • Dec 26, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›