CVE-2013-3663: Google Sketchup

High severity, CVSS 9.3. EPSS: 31.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, allows remote attackers to execute arbitrary code via a crafted RLE8 compressed BMP.

Affected products

  • Google Sketchup: up to and including 8.0; version 6.0 only; version 7.0 only; version 7.1 only; version 8.0 only

Published 2014-06-13. Last modified 2026-06-16.