Vulnerabilities > Blender > Blender > 2.40

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2022-0544 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file.
local
low complexity
blender debian CWE-191
5.5
2022-02-24 CVE-2022-0545 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded.
local
low complexity
blender debian CWE-190
7.8
2009-11-06 CVE-2009-3850 Code Injection vulnerability in Blender
Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
network
blender CWE-94
critical
9.3