A weakness has been identified in Open Asset Import Library Assimp 6.0.2 affecting the Q3DImporter::InternReadFile function. Exploitation can lead to a local heap-based buffer overflow. The exploit is available publicly.
CVE-2025-11277
🟡 Medium
CVE-2025-11277: Local Heap-Based Buffer Overflow in Assimp 6.0.2
A vulnerability in Assimp 6.0.2 allows for local heap-based buffer overflow through the Q3DImporter::InternReadFile function. Exploits are public.
CVE ID
CVE-2025-11277
CVSS Score
5.3
Vendor
unknown
Published
Oct 05
Vulnerability Details
- CVE ID
- CVE-2025-11277
- Severity
- Medium
- CVSS v3 Score
- 5.3 / 10.0
- Affected Vendor
- unknown
- Publication Date
- October 05, 2025
External Resources
Need Help?
Protect your infrastructure with our comprehensive security scanning tools.
Explore Security Scanners