<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:29:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-323952</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323952</link>
      <description>EUVD-2026-323952</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323952</guid>
    </item>
    <item>
      <title>fkie_cve-2026-10232</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10232</link>
      <description>&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-10232</guid>
    </item>
    <item>
      <title>GHSA-7vqg-xr22-fvmv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7vqg-xr22-fvmv</link>
      <description>&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7vqg-xr22-fvmv</guid>
    </item>
    <item>
      <title>OESA-2026-3104 — assimp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3104</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: assimp&lt;/p&gt;
&lt;p&gt;Assimp is a library to load and process geometric scenes from various data formats. Assimp aims to provide a full asset conversion pipeline for use in game engines and real-time rendering systems of any kind, but is not limited to this purpose.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation(CVE-2025-70067)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method(CVE-2025-70069)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()(CVE-2025-70070)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()(CVE-2025-70071)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components(CVE-2025-70072)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: assimp&lt;/p&gt;
&lt;p&gt;Assimp is a library to load and process geometric scenes from various data formats. Assimp aims to provide a full asset conversion pipeline for use in game engines and real-time rendering systems of any kind, but is not limited to this purpose.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation(CVE-2025-70067)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method(CVE-2025-70069)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()(CVE-2025-70070)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()(CVE-2025-70071)&lt;/p&gt;
&lt;p&gt;An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components(CVE-2025-70072)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3104</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11129-1 — assimp-devel-6.0.5-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11129-1</link>
      <description>&lt;p&gt;assimp-devel-6.0.5-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;assimp-devel-6.0.5-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11129-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-10232</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10232</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: assimp, Ubuntu:18.04:LTS: assimp, Ubuntu:20.04:LTS: assimp, Ubuntu:22.04:LTS: assimp, Ubuntu:24.04:LTS: assimp, Ubuntu:25.10: assimp, Ubuntu:26.04:LTS: assimp&lt;/p&gt;
&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: assimp, Ubuntu:18.04:LTS: assimp, Ubuntu:20.04:LTS: assimp, Ubuntu:22.04:LTS: assimp, Ubuntu:24.04:LTS: assimp, Ubuntu:25.10: assimp, Ubuntu:26.04:LTS: assimp&lt;/p&gt;
&lt;p&gt;A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10232</guid>
    </item>
  </channel>
</rss>
