8.4
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.
AI Analysis
A stack-based buffer overflow in the LoadOFF function of bullet3's VHACD utility allows remote attackers to execute arbitrary code via maliciously crafted OFF files.
Basic Information
ID
CVE-2025-8854
Source
CyberArk
Published
Aug 11, 2025 at 04:24
Affected Product
Vendor
bulletphysics
Product
bullet3
Version
<= 3.25
Affected Versions
bulletphysics bullet3 <= 3.25
CWE Classification
AI Assessment
AI Severity
High
Vendor
Bullet Physics Community
Product
bullet3
Version
<= 3.25