VYPR

Openexr

by Openexr

pypi: openexr

Source repositories

CVEs (82)

  • CVE-2021-3474MedMar 30, 2021
    risk 0.35cvss 5.3epss 0.02

    There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.

  • CVE-2026-44663MedJun 18, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp leads to a heap-buffer overflow when…

  • CVE-2021-20303MedMar 4, 2022
    risk 0.33cvss 6.1epss 0.01

    A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer overflow, leading to an out-of-bounds write on the heap. The greatest impact of this flaw is to…

  • CVE-2026-34380MedApr 6, 2026
    risk 0.31cvss 5.9epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in…

  • CVE-2025-48074MedAug 1, 2025
    risk 0.29cvss 5.5epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory…

  • CVE-2021-20302MedMar 4, 2022
    risk 0.29cvss 5.5epss 0.01

    A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20300MedMar 4, 2022
    risk 0.29cvss 5.5epss 0.01

    A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20296MedApr 1, 2021
    risk 0.28cvss 5.3epss 0.02

    A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to…

  • CVE-2018-18443MedOct 17, 2018
    risk 0.28cvss 4.3epss 0.02

    OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview.

  • CVE-2026-39886MedApr 21, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 have a signed integer overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG 2000) decompression…

  • CVE-2026-34589MedApr 6, 2026
    risk 0.26cvss 5.0epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed…

  • CVE-2024-31047LowApr 8, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.

  • CVE-2009-1720Jul 31, 2009
    risk 0.01cvss epss 0.06

    Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the…

  • CVE-2021-45942MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.02

    OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

  • CVE-2020-16589MedDec 9, 2020
    risk 0.00cvss 5.5epss 0.01

    A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.

  • CVE-2020-16588MedDec 9, 2020
    risk 0.00cvss 5.5epss 0.01

    A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.

  • CVE-2020-16587MedDec 9, 2020
    risk 0.00cvss 5.5epss 0.01

    A heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in ImfMultiPartInputFile.cpp that can cause a denial of service via a crafted EXR file.

  • CVE-2020-15306MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.

  • CVE-2020-15305MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.

  • CVE-2020-15304MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.

Page 4 of 5