Tinyexr
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12688 | Cri | 0.64 | 9.8 | 0.02 | Jun 22, 2018 | tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. | ||
| CVE-2018-12503 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h. | ||
| CVE-2018-12092 | Cri | 0.64 | 9.8 | 0.02 | Jun 11, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. | ||
| CVE-2018-12064 | Cri | 0.64 | 9.8 | 0.01 | Jun 8, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h. | ||
| CVE-2022-34300 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. | ||
| CVE-2022-38529 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2022 | tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress. | ||
| CVE-2020-18430 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2021 | tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS). | ||
| CVE-2020-18428 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2021 | tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS). | ||
| CVE-2018-12687 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2018 | tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. | ||
| CVE-2018-12504 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2018 | tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h. | ||
| CVE-2018-12093 | Hig | 0.49 | 7.5 | 0.01 | Jun 11, 2018 | tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h. | ||
| CVE-2018-20652 | Med | 0.42 | 6.5 | 0.01 | Jan 1, 2019 | An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception. | ||
| CVE-2020-19490 | Med | 0.00 | 5.5 | 0.01 | Jul 21, 2021 | tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. |
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
- risk 0.64cvss 9.8epss 0.01
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
- risk 0.57cvss 8.8epss 0.01
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
- risk 0.51cvss 7.8epss 0.00
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
- risk 0.49cvss 7.5epss 0.01
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
- risk 0.49cvss 7.5epss 0.02
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
- risk 0.42cvss 6.5epss 0.01
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.
- risk 0.00cvss 5.5epss 0.01
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.