📦 Openexr

by Openexr

🔍 What is Openexr?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-5841

CRITICAL CVSS 9.1 Feb 1, 2024

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting a heap-based buffer overflow in OpenEXR image parsing library. It affects any application that pr...

CVE-2025-12495

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems running vulnerable versions of Academy Software Founda...

CVE-2025-12839

HIGH CVSS 7.8 Dec 23, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious EXR image files. It affects systems running vulnerable versions of the Academy Software Fo...

CVE-2025-12840

HIGH CVSS 7.8 Dec 23, 2025

This is a heap-based buffer overflow vulnerability in Academy Software Foundation OpenEXR's EXR file parsing. Attackers can execute arbitrary code by tricking users into opening malicious EXR files or...

CVE-2025-64182

HIGH CVSS 7.8 Nov 10, 2025

This vulnerability in OpenEXR's deprecated Python adapter allows memory corruption when processing malicious EXR files. Attackers can cause crashes or potentially execute arbitrary code by exploiting ...

CVE-2025-64183

HIGH CVSS 7.5 Nov 10, 2025

This CVE describes a use-after-free vulnerability in OpenEXR's Python wrapper that occurs when reading EXR image files. Attackers could exploit this to cause crashes or potentially execute arbitrary c...

CVE-2025-64181

HIGH CVSS 7.5 Nov 10, 2025

OpenEXR versions 3.3.0-3.3.5 and 3.4.0-3.4.2 contain a use of uninitialized memory vulnerability in the generic_unpack function. This can cause undefined behavior, crashes, or denial of service when p...

CVE-2021-23169

HIGH CVSS 8.8 Jun 8, 2021

CVE-2021-23169 is a heap-buffer overflow vulnerability in OpenEXR's copyIntoFrameBuffer function that allows attackers to execute arbitrary code with the permissions of the user running the vulnerable...

CVE-2025-48074

MEDIUM CVSS 5.5 Aug 1, 2025

OpenEXR 3.3.2 has a vulnerability where it trusts unvalidated dataWindow size values from file headers, allowing malicious EXR files to trigger excessive memory allocation. This can cause performance ...