cbcvebase.

Debian Openexr vulnerabilities

57 known vulnerabilities affecting debian/openexr.

Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM39LOW7

Vulnerabilities

Page 3 of 3
CVE-2021-20300P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20300 [MEDIUM] CVE-2021-20300: openexr - A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfH... A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: resolved (fixed in 2.5.4-1
debian
CVE-2020-15306P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15306 [MEDIUM] CVE-2020-15306: openexr - An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes ... An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2021-3598P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-3598 [MEDIUM] CVE-2021-3598: openexr - There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions p... There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.5.7-1) bullseye: resolved (fixed in 2.5.4-
debian
CVE-2020-11765P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11765 [MEDIUM] CVE-2020-11765: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in... An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (
debian
CVE-2021-23215P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-23215 [MEDIUM] CVE-2021-23215: openexr - An integer overflow leading to a heap-buffer overflow was found in the DwaCompre... An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. Scope: local bookworm: resolved (fixed in 2.5.7-1) bullseye: resolved (fixed in 2.5.4-2+deb11u1) forky: resolved (fixed in 2.5.7-1) sid: resolved (fixed in 2.5.7-1)
debian
CVE-2021-26260P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-26260 [MEDIUM] CVE-2021-26260: openexr - An integer overflow leading to a heap-buffer overflow was found in the DwaCompre... An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215. Scope: local bookworm: resolved (fixed in 2.5.7-1) bullseye: resolved (fixed in 2.5.4-2+deb11u1) forky: resolved (fixed
debian
CVE-2021-3605P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-3605 [MEDIUM] CVE-2021-3605: openexr - There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0... There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.5.7-1) bullseye: resolved (fixed in 2.5.4-2+deb11u1)
debian
CVE-2021-20302P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20302 [MEDIUM] CVE-2021-20302: openexr - A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an ... A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.5.4-1) bullseye: resolved (fixed in 2.5.4-1
debian
CVE-2020-15305P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15305 [MEDIUM] CVE-2020-15305: openexr - An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use... An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in
debian
CVE-2025-48074P4MEDIUMCVSS 4.6fixed in openexr 3.4.6+ds-1 (forky)2025
CVE-2025-48074 [MEDIUM] CVE-2025-48074: openexr - OpenEXR provides the specification and reference implementation of the EXR file ... OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in versio
debian
CVE-2020-16589P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16589 [MEDIUM] CVE-2020-16589: openexr - A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0... A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in
debian
CVE-2021-3933P4MEDIUMCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-3933 [MEDIUM] CVE-2021-3933: openexr - An integer overflow could occur when OpenEXR processes a crafted file on systems... An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths. Scope: local bookworm: resolved (fixed in 3.1.5-2) bullseye: resolved (fixed in 2.5.4-2+deb11u1) forky: reso
debian
CVE-2021-26945P4LOWCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-26945 [MEDIUM] CVE-2021-26945: openexr - An integer overflow leading to a heap-buffer overflow was found in OpenEXR in ve... An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. Scope: local bookworm: resolved (fixed in 3.1.5-2) bullseye: open forky: resolved (fixed in 3.1.5-2) sid: resolved (fixed in 3.1.5-2) trixie: resolved (fixed in 3.1.5-2)
debian
CVE-2020-15304P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15304 [MEDIUM] CVE-2020-15304: openexr - An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file cou... An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (
debian
CVE-2020-16588P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16588 [MEDIUM] CVE-2020-16588: openexr - A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3... A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.
debian
CVE-2018-18443P4LOWCVSS 4.3fixed in openexr 2.5.3-2 (bookworm)2018
CVE-2018-18443 [MEDIUM] CVE-2018-18443: openexr - OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool... OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview. Scope: local bookworm: resolved (fixed in 2.5.3-2) bullseye: resolved (fixed in 2.5.3-2) forky: resolved (fixed in 2.5.3-2) sid: resolved (fixed in 2.5.3-2) trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2024-31047P4LOWCVSS 3.3fixed in openexr 3.1.13-1 (forky)2024
CVE-2024-31047 [LOW] CVE-2024-31047: openexr - An issue in Academy Software Foundation openexr v.3.2.3 and before allows a loca... An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 3.1.13-1) sid: resolved (fixed in 3.1.13-1) trixie: resolved (fixed in 3.1.13-1)
debian
Debian Openexr vulnerabilities | cvebase