CVE-2018-18224
Summary
| CVE | CVE-2018-18224 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-19 22:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or cause a crash. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Opendesign | Drawings Sdk | 2019 | update1 | All | All |
| Application | Opendesign | Drawings Sdk | 2019 | update1 | All | All |
| Application | Oracle | Outside In Technology | 8.5.3 | All | All | All |
| Application | Oracle | Outside In Technology | 8.5.4 | All | All | All |
| Application | Oracle | Outside In Technology | 8.5.3 | All | All | All |
| Application | Oracle | Outside In Technology | 8.5.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Outside In Technology Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CPU Oct 2018 | CONFIRM | www.oracle.com | Vendor Advisory |
| www.opendesign.com/security-advisories | CONFIRM | www.opendesign.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.