Opendesign

    Dashboard / Vendors

    Products: 8
    Vulnerabilities: 50
    Known Exploited: 0
    1
    Critical Level Threats
    47
    High Level Threats
    0
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-10021

    A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation units (Static Initialization Order Fiasco), the application accesses uninitialized memory. This results in application crash on startup, causing denial of service. Due to undefined behavior,  memory corruption and potential arbitrary code execution cannot be ruled out in specific exploitation scenarios.

    Last Modified: Apr 15, 2026
    Published: Dec 22, 2025

    CVE-2023-5180

    Out-of-bounds Write vulnerability exists in ODA Drawings SDK before 2024.12

    Last Modified: Nov 21, 2024
    Published: Dec 26, 2023

    CVE-2023-5179

    An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.

    Last Modified: Nov 21, 2024
    Published: Nov 07, 2023

    CVE-2023-22669

    Parsing of DWG files in Open Design Alliance Drawings SDK before 2023.6 lacks proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Last Modified: May 05, 2025
    Published: Apr 15, 2023

    CVE-2023-22670

    A heap-based buffer overflow exists in the DXF file reading procedure in Open Design Alliance Drawings SDK before 2023.6. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of the length of user-supplied XRecord data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

    Last Modified: May 05, 2025
    Published: Apr 15, 2023
    Items Per Page
    Opendesign Vulnerabilities & Security CVEs | CVE-DB