📦 Assimp

by Assimp

🔍 What is Assimp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-48423

HIGH CVSS 7.8 Oct 24, 2024

A use-after-free vulnerability in assimp v5.4.3 allows local attackers to execute arbitrary code via the CallbackToLogRedirector function. This affects applications using the Assimp library for 3D mod...

CVE-2024-45679

HIGH CVSS 8.4 Sep 18, 2024

A heap-based buffer overflow vulnerability in Assimp versions before 5.4.3 allows local attackers to execute arbitrary code by importing a specially crafted file. This affects any application using vu...

CVE-2024-40724

HIGH CVSS 7.8 Jul 19, 2024

A heap-based buffer overflow vulnerability in Assimp (Open Asset Import Library) allows local attackers to execute arbitrary code by processing specially crafted files. This affects applications using...

CVE-2025-11277

MEDIUM CVSS 5.3 Oct 5, 2025

A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's Q3D file parser. Attackers with local access can execute arbitrary code by providing a malicious Q3D file. This affects any applicat...

CVE-2025-11275

MEDIUM CVSS 5.3 Oct 5, 2025

A heap-based buffer overflow vulnerability exists in Assimp 6.0.2's ODDLParser::getNextSeparator function. This allows local attackers to potentially execute arbitrary code or crash applications using...

CVE-2025-3548

MEDIUM CVSS 5.3 Apr 14, 2025

This critical vulnerability in Open Asset Import Library (Assimp) allows heap-based buffer overflow via the aiString::Set function when processing malicious 3D model files. Attackers can execute arbit...

CVE-2025-3158

MEDIUM CVSS 5.3 Apr 3, 2025

A critical heap-based buffer overflow vulnerability exists in Assimp's LWO file handler. Attackers can exploit this by crafting malicious LWO files to potentially execute arbitrary code or crash appli...

CVE-2025-3015

MEDIUM CVSS 6.3 Mar 31, 2025

This critical vulnerability in Assimp's ASE file handler allows remote attackers to trigger out-of-bounds memory reads by manipulating specially crafted ASE files. This affects any application using A...

CVE-2025-2757

MEDIUM CVSS 6.3 Mar 25, 2025

A critical heap-based buffer overflow vulnerability in Assimp's MD5 file parser allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted MD5 files. Thi...

CVE-2025-2754

MEDIUM CVSS 6.3 Mar 25, 2025

A critical heap-based buffer overflow vulnerability in Assimp's AC3D file handler allows remote attackers to execute arbitrary code or crash applications by providing specially crafted AC3D files. Thi...

CVE-2025-2751

MEDIUM CVSS 4.3 Mar 25, 2025

This vulnerability in Assimp's CSM file handler allows remote attackers to trigger an out-of-bounds read by manipulating the 'na' argument. This could lead to information disclosure or application cra...

CVE-2025-2591

MEDIUM CVSS 4.3 Mar 21, 2025

A divide-by-zero vulnerability in Assimp's MDL file parser allows remote attackers to cause denial of service by providing specially crafted Quake 1 model files. This affects applications using Assimp...

CVE-2025-2152

MEDIUM CVSS 6.3 Mar 10, 2025

A critical heap-based buffer overflow vulnerability in Assimp's BaseImporter::ConvertToUTF8 function allows remote attackers to execute arbitrary code or crash applications. This affects any software ...

CVE-2025-2151

MEDIUM CVSS 6.3 Mar 10, 2025

A critical stack-based buffer overflow vulnerability in Assimp's GetNextLine function allows remote attackers to execute arbitrary code or crash applications. This affects any software using the vulne...

CVE-2024-48425

MEDIUM CVSS 5.5 Oct 24, 2024

This CVE describes a null pointer dereference vulnerability in the Assimp library's mesh processing function that can cause segmentation faults. It affects applications using Assimp to parse 3D model ...