Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-34588

4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-34588

4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-34588

4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-34588

4 месяца назад

OpenEXR provides the specification and reference implementation of the ...

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:19359

2 месяца назад

Important: openexr security update

EPSS: Низкий
rocky логотип

RLSA-2026:19146

2 месяца назад

Important: openexr security update

EPSS: Низкий
rocky логотип

RLSA-2026:15888

3 месяца назад

Important: openexr security update

EPSS: Низкий
rocky логотип

RLSA-2026:15887

3 месяца назад

Important: openexr security update

EPSS: Низкий
github логотип

GHSA-588r-cr5c-w6hf

4 месяца назад

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19359

около 1 месяца назад

ELSA-2026-19359: openexr security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-15888

3 месяца назад

ELSA-2026-15888: openexr security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-15887

3 месяца назад

ELSA-2026-15887: openexr security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20605-1

3 месяца назад

Security update for openexr

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-34588

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 7.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-34588

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-34588

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CVSS3: 7.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-34588

OpenEXR provides the specification and reference implementation of the ...

CVSS3: 7.8
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:19359

Important: openexr security update

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:19146

Important: openexr security update

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:15888

Important: openexr security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:15887

Important: openexr security update

0%
Низкий
3 месяца назад
github логотип
GHSA-588r-cr5c-w6hf

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

CVSS3: 7.8
0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19359

ELSA-2026-19359: openexr security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-15888

ELSA-2026-15888: openexr security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-15887

ELSA-2026-15887: openexr security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20605-1

Security update for openexr

3 месяца назад

Уязвимостей на страницу