← Back

CVE-2026-42480

nvd nist
Published: May 1, 2026Modified: Jun 1, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because the quoted-string escape handler uses ptr[++anOffset] without proper bounds checking, which can read past the end of a fixed-size stack buffer.

Affected (7)

1 product
Open Cascade Technology
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Opencascade
Up to 7.9.3
Version 8.0.0 beta1
Version 8.0.0 rc1
Version 8.0.0 rc2
Version 8.0.0 rc3
Version 8.0.0 rc4
Version 8.0.0 rc5

References (1)

Timeline

No history available yet.