CVE-2025-11015: Ogrecave Ogre
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes mismatched memory management routines. The attack is restricted to local execution. The exploit has been made available to the public and could be exploited.
Affected products
- Ogrecave Ogre: version 14.4.0 only; version 14.4.1 only
Published 2025-09-26. Last modified 2026-10-09.