Debian Openexr vulnerabilities
57 known vulnerabilities affecting debian/openexr.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM39LOW7
Vulnerabilities
Page 3 of 3
CVE-2021-20300P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20300 [MEDIUM] CVE-2021-20300: openexr - A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfH...
A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1
debian
CVE-2020-15306P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15306 [MEDIUM] CVE-2020-15306: openexr - An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes ...
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2021-3598P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-3598 [MEDIUM] CVE-2021-3598: openexr - There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions p...
There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.4-
debian
CVE-2020-11765P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-11765 [MEDIUM] CVE-2020-11765: openexr - An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in...
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (
debian
CVE-2021-23215P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-23215 [MEDIUM] CVE-2021-23215: openexr - An integer overflow leading to a heap-buffer overflow was found in the DwaCompre...
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
forky: resolved (fixed in 2.5.7-1)
sid: resolved (fixed in 2.5.7-1)
debian
CVE-2021-26260P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-26260 [MEDIUM] CVE-2021-26260: openexr - An integer overflow leading to a heap-buffer overflow was found in the DwaCompre...
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
forky: resolved (fixed
debian
CVE-2021-3605P4MEDIUMCVSS 5.5fixed in openexr 2.5.7-1 (bookworm)2021
CVE-2021-3605 [MEDIUM] CVE-2021-3605: openexr - There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0...
There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
debian
CVE-2021-20302P4MEDIUMCVSS 5.5fixed in openexr 2.5.4-1 (bookworm)2021
CVE-2021-20302 [MEDIUM] CVE-2021-20302: openexr - A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an ...
A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single-part non-image to be processed by OpenEXR, to trigger a floating-point exception error. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.5.4-1)
bullseye: resolved (fixed in 2.5.4-1
debian
CVE-2020-15305P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15305 [MEDIUM] CVE-2020-15305: openexr - An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use...
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in
debian
CVE-2025-48074P4MEDIUMCVSS 4.6fixed in openexr 3.4.6+ds-1 (forky)2025
CVE-2025-48074 [MEDIUM] CVE-2025-48074: openexr - OpenEXR provides the specification and reference implementation of the EXR file ...
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in versio
debian
CVE-2020-16589P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16589 [MEDIUM] CVE-2020-16589: openexr - A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0...
A head-based buffer overflow exists in Academy Software Foundation OpenEXR 2.3.0 in writeTileData in ImfTiledOutputFile.cpp that can cause a denial of service via a crafted EXR file.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in
debian
CVE-2021-3933P4MEDIUMCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-3933 [MEDIUM] CVE-2021-3933: openexr - An integer overflow could occur when OpenEXR processes a crafted file on systems...
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.
Scope: local
bookworm: resolved (fixed in 3.1.5-2)
bullseye: resolved (fixed in 2.5.4-2+deb11u1)
forky: reso
debian
CVE-2021-26945P4LOWCVSS 5.5fixed in openexr 3.1.5-2 (bookworm)2021
CVE-2021-26945 [MEDIUM] CVE-2021-26945: openexr - An integer overflow leading to a heap-buffer overflow was found in OpenEXR in ve...
An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
Scope: local
bookworm: resolved (fixed in 3.1.5-2)
bullseye: open
forky: resolved (fixed in 3.1.5-2)
sid: resolved (fixed in 3.1.5-2)
trixie: resolved (fixed in 3.1.5-2)
debian
CVE-2020-15304P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-15304 [MEDIUM] CVE-2020-15304: openexr - An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file cou...
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (
debian
CVE-2020-16588P4MEDIUMCVSS 5.5fixed in openexr 2.5.3-2 (bookworm)2020
CVE-2020-16588 [MEDIUM] CVE-2020-16588: openexr - A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3...
A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.
debian
CVE-2018-18443P4LOWCVSS 4.3fixed in openexr 2.5.3-2 (bookworm)2018
CVE-2018-18443 [MEDIUM] CVE-2018-18443: openexr - OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool...
OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview.
Scope: local
bookworm: resolved (fixed in 2.5.3-2)
bullseye: resolved (fixed in 2.5.3-2)
forky: resolved (fixed in 2.5.3-2)
sid: resolved (fixed in 2.5.3-2)
trixie: resolved (fixed in 2.5.3-2)
debian
CVE-2024-31047P4LOWCVSS 3.3fixed in openexr 3.1.13-1 (forky)2024
CVE-2024-31047 [LOW] CVE-2024-31047: openexr - An issue in Academy Software Foundation openexr v.3.2.3 and before allows a loca...
An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.1.13-1)
sid: resolved (fixed in 3.1.13-1)
trixie: resolved (fixed in 3.1.13-1)
debian
← Previous3 / 3