Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42464 | Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacker to write a controlled value at a controlled memory location, which could result in the disclosure of sensitive memory content. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
Wed, 13 Nov 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-787 |
Tue, 12 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe substance 3d Painter |
|
| CPEs | cpe:2.3:a:adobe:substance_3d_painter:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adobe
Adobe substance 3d Painter |
|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacker to write a controlled value at a controlled memory location, which could result in the disclosure of sensitive memory content. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Title | Substance3D - Painter | Write-what-where Condition (CWE-123) | |
| Weaknesses | CWE-123 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2024-11-12T20:25:31.310Z
Reserved: 2024-09-24T17:40:22.372Z
Link: CVE-2024-47438
Updated: 2024-11-12T20:16:44.234Z
Status : Analyzed
Published: 2024-11-12T20:15:10.720
Modified: 2024-11-13T19:13:57.320
Link: CVE-2024-47438
No data.
OpenCVE Enrichment
No data.
EUVD