OpenEXR 2.5.9

CPE Details

OpenEXR 2.5.9
2.5.9
2024-02-08 14:18 +00:00
2024-02-08 14:18 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:openexr:openexr:2.5.9:*:*:*:*:*:*:*

Informations

Vendor

openexr

Product

openexr

Version

2.5.9

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-5841 2024-02-01 18:28 +00:00 Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
9.1
CRITICAL
CVE-2021-3933 2022-03-24 23:00 +00:00 An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
5.5
MEDIUM
CVE-2021-3605 2021-08-24 22:00 +00:00 There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
5.5
MEDIUM
CVE-2021-3598 2021-07-05 22:00 +00:00 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
5.5
MEDIUM
CVE-2021-26945 2021-06-08 09:39 +00:00 An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
5.5
MEDIUM
CVE-2021-23169 2021-06-07 22:00 +00:00 A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
8.8
HIGH
CVE-2021-23215 2021-06-07 22:00 +00:00 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
5.5
MEDIUM
CVE-2021-26260 2021-06-07 22:00 +00:00 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.
5.5
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.