Search CVE reports


Toggle filters

31 – 40 of 52 results


CVE-2020-11765

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11764

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11763

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11762

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11761

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11760

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11759

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2020-11758

Medium priority
Fixed

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2018-18444

Low priority

Some fixes available 5 of 6

makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Fixed Fixed Fixed
Show less packages

CVE-2018-18443

Negligible priority
Ignored

OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview.

1 affected package

openexr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openexr Not affected Not affected
Show less packages