CVE-2024-8894 is an out-of-bounds write vulnerability affecting Open Design Alliance Drawings SDK versions prior to 2025.10. An attacker can trigger an unhandled exception by crafting a malicious DWF file that lacks proper checks on received SectionIterator data. This vulnerability has a high CVSS score of 8.1, indicating a significant risk of denial-of-service through crashes, exits, or restarts, with potential for code execution. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Open Design Alliance | ODA Drawings SDK - All Versions < 2025.10 | >= 0, < 2025.10CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.