Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42216

Опубликовано: 07 мая 2026
Источник: nvd
CVSS3: 9.1
CVSS3: 8.1
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.2.9 (исключая)
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.3.11 (исключая)
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.11 (исключая)

EPSS

Процентиль: 30%
0.00376
Низкий

9.1 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-125
CWE-130

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

CVSS3: 8.1
redhat
3 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

CVSS3: 9.1
debian
3 месяца назад

OpenEXR provides the specification and reference implementation of the ...

oracle-oval
19 дней назад

ELSA-2026-38498: openexr security update (IMPORTANT)

suse-cvrf
3 месяца назад

Security update for openexr

EPSS

Процентиль: 30%
0.00376
Низкий

9.1 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-125
CWE-130