CVE-2026-59981OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-68514OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep images Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-68515OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-68513OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-65979OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-62986OpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosure Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-61555OpenEXR: Empty multiView viewFromChannelName file crash Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-59985OpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32 Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-59984OpenEXR: Scratch buffer overflow decoding B44-compressed InputFile on ILP32 Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-59983OpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode on ILP32 Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-59982OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-59189OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow origin Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-59187OpenEXR: exrmetrics deep pixelmode heap buffer overflow Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-59186OpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow on 32-bit (ILP32) builds Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-59184OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity High CVE-2026-59183OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-55373OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample counts Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-55371OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length Exploitation status Not known exploited Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-55059OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerability Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Medium CVE-2026-54920OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize Exploitation status Public exploit Fix YesAffected product O openexr Published 08/25/2026 Severity Informational CVE-2026-53532OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) Exploitation status Public exploit Fix YesAffected product O openexr Published 08/24/2026 Severity High CVE-2026-68516OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow Exploitation status Public exploit Fix YesAffected product O openexr Published 08/24/2026 Severity Medium CVE-2026-42450OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser Exploitation status Public exploit Fix Not confirmed Affected product O OpenColorIO Published 06/24/2026 Severity High CVE-2026-45696OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) Exploitation status Public exploit Fix YesAffected product O openexr Published 06/18/2026 Severity High CVE-2026-44663OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow Exploitation status Not known exploited Fix YesAffected product O openexr Published 06/18/2026 Severity Medium CVE-2026-43903OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release builds Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43904OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image width Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43905OpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocation Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43996OpenImageIO: Integer wraparound in bounds check of decode_pixel leads to out-of-bounds read in TGA paletted image decoder Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity Medium CVE-2026-43907OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR) Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43908OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoder Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43909OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoder Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-43906OpenImageIO: HEIF Heap overflow Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/14/2026 Severity High CVE-2026-42217OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`) Exploitation status Public exploit Fix YesAffected product O openexr Published 05/07/2026 Severity Medium CVE-2026-42216OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion Exploitation status Public exploit Fix YesAffected product O openexr Published 05/07/2026 Severity High CVE-2026-41142OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API Exploitation status Not known exploited Fix YesAffected product O openexr Published 05/07/2026 Severity High CVE-2026-7582AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write Exploitation status Public exploit Fix YesAffected product O OpenImageIO Published 05/01/2026 Severity Medium CVE-2026-40250OpenEXR has integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589) Exploitation status Not known exploited Fix YesAffected product O openexr Published 04/21/2026 Severity High CVE-2026-40244OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589) Exploitation status Not known exploited Fix YesAffected product O openexr Published 04/21/2026 Severity High CVE-2026-39886OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl() Exploitation status Public exploit Fix Not confirmed Affected product O openexr Published 04/21/2026 Severity Medium CVE-2026-34589OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write Exploitation status Not known exploited Fix YesAffected product O openexr Published 04/06/2026 Severity High CVE-2026-34588OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write Exploitation status Not known exploited Fix YesAffected product O openexr Published 04/06/2026 Severity High CVE-2026-34380OpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompression Exploitation status Public exploit Fix YesAffected product O openexr Published 04/06/2026 Severity Medium CVE-2026-34379OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression) Exploitation status Public exploit Fix YesAffected product O openexr Published 04/06/2026 Severity High CVE-2026-34378OpenEXR has a signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x Exploitation status Public exploit Fix YesAffected product O openexr Published 04/06/2026 Severity Medium CVE-2026-34543OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl) Exploitation status Public exploit Fix YesAffected product O openexr Published 04/01/2026 Severity High CVE-2026-34544OpenEXR: integer overflow to OOB write in uncompress_b44_impl() Exploitation status Public exploit Fix YesAffected product O openexr Published 04/01/2026 Severity High CVE-2026-34545OpenEXR: integer overflow lead to OOB in HTJ2K decoder Exploitation status Public exploit Fix YesAffected product O openexr Published 04/01/2026 Severity High CVE-2026-27622OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write Exploitation status Not known exploited Fix YesAffected product O openexr Published 03/03/2026 Severity High CVE-2026-26981OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp Exploitation status Public exploit Fix Not confirmed Affected product O openexr Published 02/24/2026 Severity Medium CVE-2025-15506AcademySoftwareFoundation OpenColorIO FileRules.cpp ConvertToRegularExpression out-of-bounds Exploitation status Public exploit Fix YesAffected product O OpenColorIO Published 01/11/2026 Severity Medium CVE-2025-64183OpenEXR has use after free in PyObject_StealAttrString Exploitation status Public exploit Fix Not confirmed Affected product O openexr Published 11/10/2025 Severity Medium CVE-2025-64182OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel() Exploitation status Public exploit Fix Not confirmed Affected product O openexr Published 11/10/2025 Severity Medium CVE-2025-64181OpenEXR Makes Use of Uninitialized Memory Exploitation status Public exploit Fix Not confirmed Affected product O openexr Published 11/10/2025 Severity Low CVE-2025-53012MaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion Exploitation status Public exploit Fix YesAffected product M MaterialX Published 08/01/2025 Severity Medium CVE-2025-53011MaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput Exploitation status Public exploit Fix YesAffected product M MaterialX Published 08/01/2025 Severity Low CVE-2025-53010MaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer Dereference Exploitation status Public exploit Fix YesAffected product M MaterialX Published 08/01/2025 Severity Low CVE-2025-53009MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit Exploitation status Public exploit Fix YesAffected product M MaterialX Published 08/01/2025 Severity Medium CVE-2025-48074OpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory Errors Exploitation status Public exploit Fix YesAffected product O openexr Published 08/01/2025 Severity Medium CVE-2025-48073OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode Exploitation status Public exploit Fix YesAffected product O openexr Published 07/31/2025 Severity Medium CVE-2025-48072OpenEXR's Inaccurate Pointer Arithmetic can Cause an Out of Bounds Heap Exploitation status Public exploit Fix YesAffected product O openexr Published 07/31/2025 Severity Medium CVE-2025-48071OpenEXR's Forged Unpacked Size can Lead to Heap-Based Buffer Overflow in Deep Scanline Parsing Exploitation status Public exploit Fix YesAffected product O openexr Published 07/31/2025 Severity High CVE-2024-40630HEIF Heap OOB Read in OpenImageIO Exploitation status Public exploit Fix Not confirmed Affected product O OpenImageIO Published 07/15/2024 Severity Medium