OpenSCAD is a specialized 3D solid modeling and design application whose vulnerability profile centers on memory-safety issues in its geometry-processing engine, including buffer overflows, out-of-bounds read and write conditions, and improper memory-bounds restrictions. These weakness classes are characteristic of the low-level computational and parsing demands inherent to solid modeling and CAD operations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openscad over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0497HIGH A vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of annotations. | Aug 29, 2022 | 7.1 | 24 | NO | NO |
CVE-2020-28600HIGH An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code executio | May 10, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-28599HIGH A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code e | Feb 24, 2021 | 7.8 | 20 | NO | NO |
CVE-2022-0496MEDIUM A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported usi | Aug 29, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openscad.
Media articles that mention a CVE ID that affects a product developed by Openscad — matched by CVE ID, not by vendor name.