Vulnerabilities > Blackmagicdesign

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-40417 Integer Overflow or Wraparound vulnerability in Blackmagicdesign Davinci Resolve 17.3.1.0005
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer.
network
low complexity
blackmagicdesign CWE-190
critical
9.8
2021-12-22 CVE-2021-40418 Use of Uninitialized Resource vulnerability in Blackmagicdesign Davinci Resolve 17.3.1.0005
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container.
network
low complexity
blackmagicdesign CWE-908
critical
9.8