CyberRota
Live Feed
Return to register
Case File

CVE-2017-2902

HIGH · CVSS 7.8 EPSS 1.84% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-04-24 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2017-2902
Severity
HIGH
CVSS
7.8
EPSS
1.84%

Original Filing — NVD Description

An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.