VYPR
Vendor

Syoyo

Products
4
CVEs
15
Across products
15
Status
Private

Products

4

Recent CVEs

15
  • CVE-2018-12688CriJun 22, 2018
    risk 0.64cvss 9.8epss 0.02

    tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.

  • CVE-2018-12503CriJun 16, 2018
    risk 0.64cvss 9.8epss 0.02

    tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.

  • CVE-2018-12092CriJun 11, 2018
    risk 0.64cvss 9.8epss 0.02

    tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

  • CVE-2018-12064CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.

  • CVE-2022-34300HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

  • CVE-2026-71266HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…

  • CVE-2022-38529HigSep 6, 2022
    risk 0.51cvss 7.8epss 0.00

    tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.

  • CVE-2020-18430HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).

  • CVE-2018-12687HigJun 22, 2018
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

  • CVE-2018-12504HigJun 16, 2018
    risk 0.49cvss 7.5epss 0.02

    tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.

  • CVE-2018-12093HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.

  • CVE-2018-20652MedJan 1, 2019
    risk 0.42cvss 6.5epss 0.01

    An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.

  • CVE-2023-1570LowMar 22, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in syoyo tinydng. Affected by this issue is the function __interceptor_memcpy of the file tiny_dng_loader.h. The manipulation leads to heap-based buffer overflow. Local access is required to approach this…

  • CVE-2022-3008HigSep 5, 2022
    risk 0.00cvss 8.1epss 0.03

    The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in…

  • CVE-2020-19490MedJul 21, 2021
    risk 0.00cvss 5.5epss 0.01

    tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.