« Volver al listado

CVE-2010-0280

Estado: ModificadaAlta (9.3)—

Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0280",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-15T17:30:00.580",
  "references": [
    {
      "url": "http://secunia.com/advisories/38185",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38187",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sketchup.google.com/support/bin/answer.py?hl=en&answer=141303",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.coresecurity.com/content/google-sketchup-vulnerability",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508913/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/37708",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0133",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38185",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38187",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sketchup.google.com/support/bin/answer.py?hl=en&answer=141303",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.coresecurity.com/content/google-sketchup-vulnerability",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508913/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37708",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0133",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c."
    },
    {
      "lang": "es",
      "value": "Error de indice de array en Jan Eric Kyprianidis lib3ds v1.x, como el utilizado en Google SketchUp v7.x anterior a 7.1 M2, permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) o puede que ejecutar código de su elección a través de estructuras manipuladas en un fichero 3DS. Puede que esté relacionado con mesh.c."
    }
  ],
  "lastModified": "2026-06-16T23:15:51.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jan_eric_krprianidis:lib3ds:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31DFFE18-61E1-4B0B-BE76-630A6E3F04C0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:google_sketchup:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1654DC5-3E08-4F09-BF95-D5ADDAC7EEB6"
            },
            {
              "criteria": "cpe:2.3:a:google:google_sketchup:7.0.10247:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51465673-7CA9-4F00-BFE6-3313020B5208"
            },
            {
              "criteria": "cpe:2.3:a:google:google_sketchup:7.1.4871:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C5C3005-EE4F-4D9E-9FFB-2146874CAAE6"
            },
            {
              "criteria": "cpe:2.3:a:google:google_sketchup:7.1.6087:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7254B40E-67A4-4A8B-B22A-B8DB99662BBD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}