VYPR

rpm package

opensuse/openexr&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/openexr&distro=openSUSE%20Tumbleweed

Vulnerabilities (58)

  • CVE-2026-68515HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-s

  • CVE-2026-68514MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap out-of-bounds write triggered when reading

  • CVE-2026-68513HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between lit

  • CVE-2026-59981HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the Sampl

  • CVE-2026-65979MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compressed data but never checks that this value

  • CVE-2026-62986MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanlin

  • CVE-2026-61555MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartF

  • CVE-2026-59985MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The i

  • CVE-2026-59984MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds write. When a c

  • CVE-2026-59983MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerabilit

  • CVE-2026-59982HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() whe

  • CVE-2026-59189HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel::row() API can return an out-of-bounds po

  • CVE-2026-59187HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanlin

  • CVE-2026-59186HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 bu

  • CVE-2026-59184HigAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::

  • CVE-2026-59183MedAug 25, 2026
    affected < 3.4.14-1.1fixed 3.4.14-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can o

  • CVE-2026-55373MedAug 25, 2026
    affected < 3.4.13-1.1fixed 3.4.13-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a sample-

  • CVE-2026-55371MedAug 25, 2026
    affected < 3.4.13-1.1fixed 3.4.13-1.1

    OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public se

  • CVE-2026-55059MedAug 25, 2026
    affected < 3.4.13-1.1fixed 3.4.13-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]).

  • CVE-2026-54920NonAug 25, 2026
    affected < 3.4.13-1.1fixed 3.4.13-1.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an uncondit

Page 1 of 3