9.3
CVSSv2

CVE-2009-3850

Published: 06/11/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Blender 2.34, 2.35a, 2.40, and 2.49b allows remote malicious users to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.

Vulnerable Product Search on Vulmon Subscribe to Product

blender blender 2.49b

blender blender 2.35a

blender blender 2.34

blender blender 2.40

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ Blender blend Project Arbitrary Command Execution 1 *Advisory Information* Title: Blender blend Project Arbitrary Command Execution Advisory Id: CORE-2009-0912 Advisory URL: wwwcoresec ...