VYPR

tinyexr

by Tinyexr

CVEs (5)

  • CVE-2022-34300HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

  • CVE-2022-38529HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.00

    tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.

  • CVE-2020-18430HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).

  • CVE-2020-18428HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).

  • CVE-2020-19490MedJul 21, 2021
    risk 0.00cvss 5.5epss 0.01

    tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.