Academy Software Foundation Openexr vulnerabilities
4 known vulnerabilities affecting academy_software_foundation/openexr.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3
Vulnerabilities
Page 1 of 1
CVE-2025-12495HIGHCVSS 7.8v3.4.02025-12-23
CVE-2025-12495 [HIGH] CWE-122 CVE-2025-12495: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executio
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious
nvd
CVE-2025-12839HIGHCVSS 7.8v3.4.02025-12-23
CVE-2025-12839 [HIGH] CWE-122 CVE-2025-12839: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executio
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious
nvd
CVE-2025-12840HIGHCVSS 7.8v3.4.02025-12-23
CVE-2025-12840 [HIGH] CWE-122 CVE-2025-12840: Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Executio
Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious
nvd
CVE-2023-5841CRITICALCVSS 9.1≤ 3.2.12024-02-01
CVE-2023-5841 [CRITICAL] CWE-122 CVE-2023-5841: Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scan
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.
nvd