Vulnerabilities > Openimageio > Openimageio > 2.3.19.0

DATE CVE VULNERABILITY TITLE RISK
2023-07-03 CVE-2023-36183 Classic Buffer Overflow vulnerability in Openimageio
Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.
local
low complexity
openimageio CWE-120
7.8
2022-12-22 CVE-2022-36354 Off-by-one Error vulnerability in multiple products
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0.
network
low complexity
openimageio debian CWE-193
5.3
2022-12-22 CVE-2022-38143 Write-what-where Condition vulnerability in Openimageio 2.3.19.0
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images.
network
low complexity
openimageio CWE-123
critical
9.8
2022-12-22 CVE-2022-41639 Heap-based Buffer Overflow vulnerability in multiple products
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0.
network
low complexity
openimageio debian CWE-122
critical
9.8
2022-12-22 CVE-2022-41649 Out-of-bounds Read vulnerability in multiple products
A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0.
network
low complexity
openimageio debian CWE-125
critical
9.1
2022-12-22 CVE-2022-41794 Heap-based Buffer Overflow vulnerability in multiple products
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0.
network
low complexity
openimageio debian CWE-122
critical
9.8
2022-12-22 CVE-2022-41977 Out-of-bounds Read vulnerability in Openimageio 2.3.19.0
An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files.
local
low complexity
openimageio CWE-125
3.3
2022-12-22 CVE-2022-41981 Stack-based Buffer Overflow vulnerability in multiple products
A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0.
network
high complexity
openimageio debian CWE-121
8.1
2022-12-22 CVE-2022-41988 Out-of-bounds Read vulnerability in multiple products
An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0.
network
low complexity
openimageio debian CWE-125
7.5
2022-12-22 CVE-2022-41999 NULL Pointer Dereference vulnerability in multiple products
A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2.
network
low complexity
openimageio debian CWE-476
7.5