Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in m3dsafestr (called from m3d_load and Assimp::M3DWrapper::M3DWrapper).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-45948.json"