ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-38529
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.

tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.

NVD description · AI analysis pending
7.8<1% PoC
  • tinyexr project tinyexr
CVE-2022-34300
In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

NVD description · AI analysis pending
8.82% PoC
  • tinyexr project tinyexr
CVE-2020-18430
+1 in the same advisory: …18428
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).

tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).

NVD description · AI analysis pending
7.51% PoC ×2
  • tinyexr project tinyexr
CVE-2020-19490
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

NVD description · AI analysis pending
5.5<1% PoC
  • tinyexr project tinyexr
CVE-2018-20652
An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5.

An attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted input, which leads to an out-of-memory exception.

NVD description · AI analysis pending
6.51% PoC
  • tinyexr project tinyexr
CVE-2018-12688
+1 in the same advisory: …12687
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.

tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.

NVD description · AI analysis pending
9.8
group max
2%
  • tinyexr project tinyexr
CVE-2018-12503
+1 in the same advisory: …12504
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.

tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.

NVD description · AI analysis pending
9.8
group max
2%
  • tinyexr project tinyexr
CVE-2018-12092
+1 in the same advisory: …12093
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

NVD description · AI analysis pending
9.8
group max
2%
  • tinyexr project tinyexr
CVE-2018-12064
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.

tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.

NVD description · AI analysis pending
9.81%
  • tinyexr project tinyexr