Openexr
openexr
78 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (78)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apple CanonicalDebian+3 more12Debian Linux FedoraIcloud+9 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. |
6Apple CanonicalDebian+3 more12Debian Linux FedoraIcloud+9 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case. |
5Apple CanonicalDebian+2 more11Debian Linux FedoraIcloud+8 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp. |
6Apple CanonicalDebian+3 more12Debian Linux FedoraIcloud+9 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp. |
5Apple CanonicalDebian+2 more11Debian Linux FedoraIcloud+8 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer. |
6Apple CanonicalDebian+3 more12Debian Linux FedoraIcloud+9 moreJun 17, 2026 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. |
Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmIm...Show more |
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact...Show more |
In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash. |
In OpenEXR 2.2.0, an invalid write of size 2 in the = operator function in half.h could cause the application to crash or execute arbitrary code. |
In OpenEXR 2.2.0, an invalid read of size 1 in the refill function in ImfFastHuf.cpp could cause the application to crash. |
In OpenEXR 2.2.0, an invalid write of size 1 in the bufferedReadPixels function in ImfInputFile.cpp could cause the application to crash or execute arbitrary code. |
In OpenEXR 2.2.0, an invalid read of size 1 in the getBits function in ImfHuf.cpp could cause the application to crash. |
In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code. |
In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash. |
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors...Show more |
6Apple CanonicalDebian+3 more6Debian Linux FedoraMac Os X+3 moreApr 23, 2026 Jul 31, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more |
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based...Show more |