CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-24685

Medium Severity
Libigl
SVRS
36/100

CVSSv3
7.8/10

EPSS
0.0116/1

CVE-2024-24685 affects libigl, potentially causing denial of service or arbitrary code execution. This buffer overflow vulnerability resides in the readOFF function when parsing specially crafted .off files.

CVE-2024-24685 is a stack-based buffer overflow vulnerability in the readOFF functionality of libigl v2.5.0. An attacker can exploit this critical flaw by providing a malicious .off file. Although the CVSS score is 7.8, indicating high severity, the SOCRadar Vulnerability Risk Score (SVRS) is 36, suggesting lower immediate risk despite active exploits being available. Still, the existence of exploit code makes this vulnerability significant. Successful exploitation could lead to denial of service or, more seriously, arbitrary code execution.

In The Wild
Exploit Avaliable
CVSS:3.1
AV:L
AC:L
PR:N
UI:R
S:U
C:H
I:H
A:H
2024-05-28

2025-02-13

Indicators of Compromise

No IOCs found for this CVE

Exploits

TitleSoftware LinkDate
SpiralBL0CK/CVE-2024-24685https://github.com/SpiralBL0CK/CVE-2024-246852024-10-15
Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-24685 | libigl 2.5.0 readOFF stack-based overflow (TALOS-2024-1929)
vuldb.com2025-02-12
CVE-2024-24685 | libigl 2.5.0 readOFF stack-based overflow (TALOS-2024-1929) | A vulnerability was found in libigl 2.5.0. It has been rated as critical. Affected by this issue is the function readOFF. The manipulation leads to stack-based buffer overflow. This vulnerability is handled as CVE-2024-24685. The attack may be launched remotely. There is no exploit available.
vuldb.com
rss
forum
news
Out-of-bounds reads in Adobe Acrobat; Foxit PDF Reader contains vulnerability that could lead to SYSTEM-level privileges
Jonathan Munshaw2024-05-29
Out-of-bounds reads in Adobe Acrobat; Foxit PDF Reader contains vulnerability that could lead to SYSTEM-level privileges | Acrobat, one of the most popular PDF readers currently available, contains two out-of-bounds read vulnerabilities that could lead to the exposure of sensitive contents of arbitrary memory in the application.Cisco Talos’ Vulnerability Research team has helped to disclose and patch more than 20 vulnerabilities over the past
cve-2024-24947
cve-2024-23947
cve-2024-24963
cve-2024-21785

Social Media

No tweets found for this CVE

Affected Software

Configuration 1
TypeVendorProduct
AppLibigllibigl

References

ReferenceLink
[email protected]https://talosintelligence.com/vulnerability_reports/TALOS-2024-1929
[email protected]https://talosintelligence.com/vulnerability_reports/TALOS-2024-1929
[email protected]https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1929
AF854A3A-2127-422B-91AE-364DA2661108https://talosintelligence.com/vulnerability_reports/TALOS-2024-1929
AF854A3A-2127-422B-91AE-364DA2661108https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1929
[email protected]https://talosintelligence.com/vulnerability_reports/TALOS-2024-1929
[email protected]https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1929
HTTPS://TALOSINTELLIGENCE.COM/VULNERABILITY_REPORTS/TALOS-2024-1929https://talosintelligence.com/vulnerability_reports/TALOS-2024-1929

CWE Details

CWE IDCWE NameDescription
CWE-121Stack-based Buffer OverflowA stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence