Back
CVE-2005-3302
HIGH
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
Published: Oct 24, 2005
Modified: Jun 16, 2026
CWE-94
CWE-94
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| blender | blender | 2.36 |
| debian | debian_linux | 3.1 |
GitHub Security Advisory GHSA-2q62-rw6m-pchg
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute...
References (8)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895 Exploit, Mailing List, Third Party Advisory
- http://secunia.com/advisories/19754 Broken Link
- http://www.debian.org/security/2006/dsa-1039 Third Party Advisory
- http://www.securityfocus.com/bid/17663 Broken Link, Third Party Advisory, VDB Entry
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330895 Exploit, Mailing List, Third Party Advisory
- http://secunia.com/advisories/19754 Broken Link
- http://www.debian.org/security/2006/dsa-1039 Third Party Advisory
- http://www.securityfocus.com/bid/17663 Broken Link, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
7.3 / 10
EPSS Score
3.88%
Top 11% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub