Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24119 | Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function. |
Mon, 08 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bulletphysics
Bulletphysics pybullet |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:bulletphysics:pybullet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bulletphysics
Bulletphysics pybullet |
|
| Metrics |
cvssV3_1
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bullet3 Project
Bullet3 Project bullet3 |
|
| Vendors & Products |
Bullet3 Project
Bullet3 Project bullet3 |
Mon, 11 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 11 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function. | |
| Title | bullet3 VHACD utility: stack-based buffer overflow in OFF parser (LoadOFF) | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CyberArk
Published:
Updated: 2025-08-11T20:32:47.464Z
Reserved: 2025-08-11T03:59:29.801Z
Link: CVE-2025-8854
Updated: 2025-08-11T20:32:36.490Z
Status : Analyzed
Published: 2025-08-11T05:15:27.187
Modified: 2025-12-08T18:58:01.813
Link: CVE-2025-8854
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:07Z
EUVD