White Dune is a niche 3D VRML/X3D modeling and animation authoring tool with a focused vulnerability footprint centered on its core product. The observed weakness classes—improper input validation, buffer-boundary issues, and format-string handling—reflect the parser and rendering demands of processing external model files and user-supplied scene data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by White Dune over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0100HIGH Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in | Jan 8, 2008 | 7.5 | 34 | NO | YES |
CVE-2017-17518HIGH swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow re | Dec 14, 2017 | 8.8 | 26 | NO | NO |
CVE-2008-7228HIGH Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101. | Sep 14, 2009 | 10.0 | 26 | NO | NO |
CVE-2008-0101HIGH Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string speci | Jan 8, 2008 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by White Dune.
Media articles that mention a CVE ID that affects a product developed by White Dune — matched by CVE ID, not by vendor name.