Vulnerabilities > Openexr > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2021-20298 Out-of-bounds Write vulnerability in multiple products
A flaw was found in OpenEXR's B44Compressor.
network
low complexity
openexr debian CWE-787
7.5
2022-08-23 CVE-2021-20304 Integer Overflow or Wraparound vulnerability in Openexr
A flaw was found in OpenEXR's hufDecode functionality.
network
low complexity
openexr CWE-190
7.5
2022-03-16 CVE-2021-20299 NULL Pointer Dereference vulnerability in multiple products
A flaw was found in OpenEXR's Multipart input file functionality.
network
low complexity
openexr debian CWE-476
7.5
2021-06-08 CVE-2021-23169 Out-of-bounds Write vulnerability in multiple products
A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1.
network
low complexity
openexr fedoraproject CWE-787
8.8
2009-07-31 CVE-2009-1720 Numeric Errors vulnerability in Openexr 1.2.2/1.6.1
Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors.
network
low complexity
openexr CWE-189
7.5