VYPR
Critical severity9.8OSV Advisory· Published Jun 11, 2018· Updated Jun 17, 2026

CVE-2018-12092

CVE-2018-12092

Description

tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

Affected products

3
  • Syoyo/TinyexrOSV2 versions
    v0.9.0, v0.9.5+ 1 more
    • (no CPE)range: v0.9.0, v0.9.5
    • (no CPE)range: =0.9.5
  • cpe:2.3:a:tinyexr_project:tinyexr:0.9.5:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.