Vendorstinyexr Projecttinyexrall versions
Vulnerabilities

tinyexr Project tnyexr Project tinyexr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2018-12503
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
Published 2018-06-16 · Modified
9.8EPSS 0.018
CVE-2018-12092
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
Published 2018-06-11 · Modified
9.8EPSS 0.016
CVE-2018-12688
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
Published 2018-06-22 · Modified
9.8EPSS 0.016
CVE-2018-12064
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
Published 2018-06-08 · Modified
9.8EPSS 0.013
CVE-2022-34300
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
Published 2022-06-22 · Modified
8.8EPSS 0.015
CVE-2022-38529
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
Published 2022-09-06 · Modified
7.8EPSS 0.003
CVE-2018-12504
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
Published 2018-06-16 · Modified
7.5EPSS 0.016
CVE-2018-12093
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
Published 2018-06-11 · Modified
7.5EPSS 0.014
CVE-2018-12687
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
Published 2018-06-22 · Modified
7.5EPSS 0.014
CVE-2020-18430
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
Published 2021-07-26 · Modified
7.5EPSS 0.013
CVE-2020-18428
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
Published 2021-07-26 · Modified
7.5EPSS 0.012
CVE-2018-20652
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.
Published 2019-01-01 · Modified
6.5EPSS 0.015
CVE-2020-19490
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
Published 2021-07-21 · Modified
5.5EPSS 0.008