VYPR
Medium severity6.5OSV Advisory· Published Jan 1, 2019· Updated Jun 17, 2026

CVE-2018-20652

CVE-2018-20652

Description

An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.

Affected products

3
  • Syoyo/TinyexrOSV2 versions
    v0.9.0, v0.9.5+ 1 more
    • (no CPE)range: v0.9.0, v0.9.5
    • (no CPE)range: <=0.9.5
  • cpe:2.3:a:tinyexr_project:tinyexr:0.9.5:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.