rpm package
opensuse/openexr&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/openexr&distro=openSUSE%20Leap%2016.0
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-34589 | Med | 5.0 | < 3.2.2-160000.6.1 | 3.2.2-160000.6.1 | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-b | |
| CVE-2026-34588 | Hig | 7.8 | < 3.2.2-160000.6.1 | 3.2.2-160000.6.1 | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmeti | |
| CVE-2026-34380 | Med | 5.9 | < 3.2.2-160000.6.1 | 3.2.2-160000.6.1 | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr | |
| CVE-2026-34379 | Hig | 7.1 | < 3.2.2-160000.6.1 | 3.2.2-160000.6.1 | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/Op | |
| CVE-2026-27622 | — | < 3.2.2-160000.5.1 | 3.2.2-160000.5.1 | Mar 3, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled larg | ||
| CVE-2025-12840 | — | < 3.2.2-160000.4.1 | 3.2.2-160000.4.1 | Dec 23, 2025 | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required | ||
| CVE-2025-12839 | — | < 3.2.2-160000.4.1 | 3.2.2-160000.4.1 | Dec 23, 2025 | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required | ||
| CVE-2025-12495 | — | < 3.2.2-160000.4.1 | 3.2.2-160000.4.1 | Dec 23, 2025 | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required | ||
| CVE-2025-64181 | — | < 3.2.2-160000.3.1 | 3.2.2-160000.3.1 | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch |
- affected < 3.2.2-160000.6.1fixed 3.2.2-160000.6.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-b
- affected < 3.2.2-160000.6.1fixed 3.2.2-160000.6.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmeti
- affected < 3.2.2-160000.6.1fixed 3.2.2-160000.6.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr
- affected < 3.2.2-160000.6.1fixed 3.2.2-160000.6.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/Op
- CVE-2026-27622Mar 3, 2026affected < 3.2.2-160000.5.1fixed 3.2.2-160000.5.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled larg
- CVE-2025-12840Dec 23, 2025affected < 3.2.2-160000.4.1fixed 3.2.2-160000.4.1
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required
- CVE-2025-12839Dec 23, 2025affected < 3.2.2-160000.4.1fixed 3.2.2-160000.4.1
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required
- CVE-2025-12495Dec 23, 2025affected < 3.2.2-160000.4.1fixed 3.2.2-160000.4.1
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required
- CVE-2025-64181Nov 10, 2025affected < 3.2.2-160000.3.1fixed 3.2.2-160000.3.1
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch