Syoyo
Products
4- 12 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12688 | Cri | 0.64 | 9.8 | 0.02 | Jun 22, 2018 | tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. | ||
| CVE-2018-12503 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h. | ||
| CVE-2018-12092 | Cri | 0.64 | 9.8 | 0.02 | Jun 11, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. | ||
| CVE-2018-12064 | Cri | 0.64 | 9.8 | 0.01 | Jun 8, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h. | ||
| CVE-2022-34300 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2022 | In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. | ||
| CVE-2026-71266 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2026 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same… | ||
| CVE-2022-38529 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2022 | tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress. | ||
| CVE-2020-18430 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2021 | tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS). | ||
| CVE-2018-12687 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2018 | tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. | ||
| CVE-2018-12504 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2018 | tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h. | ||
| CVE-2018-12093 | Hig | 0.49 | 7.5 | 0.01 | Jun 11, 2018 | tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h. | ||
| CVE-2018-20652 | Med | 0.42 | 6.5 | 0.01 | Jan 1, 2019 | An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception. | ||
| CVE-2023-1570 | Low | 0.21 | 3.3 | 0.00 | Mar 22, 2023 | A vulnerability, which was classified as problematic, has been found in syoyo tinydng. Affected by this issue is the function __interceptor_memcpy of the file tiny_dng_loader.h. The manipulation leads to heap-based buffer overflow. Local access is required to approach this… | ||
| CVE-2022-3008 | Hig | 0.00 | 8.1 | 0.03 | Sep 5, 2022 | The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in… | ||
| CVE-2020-19490 | Med | 0.00 | 5.5 | 0.01 | Jul 21, 2021 | tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. |
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
- risk 0.64cvss 9.8epss 0.02
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
- risk 0.64cvss 9.8epss 0.01
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
- risk 0.57cvss 8.8epss 0.01
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
- risk 0.51cvss 7.8epss 0.00
tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…
- risk 0.51cvss 7.8epss 0.00
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
- risk 0.49cvss 7.5epss 0.02
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
- risk 0.49cvss 7.5epss 0.01
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
- risk 0.42cvss 6.5epss 0.01
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.
- risk 0.21cvss 3.3epss 0.00
A vulnerability, which was classified as problematic, has been found in syoyo tinydng. Affected by this issue is the function __interceptor_memcpy of the file tiny_dng_loader.h. The manipulation leads to heap-based buffer overflow. Local access is required to approach this…
- risk 0.00cvss 8.1epss 0.03
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in…
- risk 0.00cvss 5.5epss 0.01
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.