openimageio records
55 published records for vendor openimageio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 90.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read16
- CWE-122 Heap-based Buffer Overflow13
- CWE-476 NULL Pointer Dereference6
- CWE-787 Out-of-bounds Write6
- CWE-190 Integer Overflow or Wraparound4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
55 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-41794No exploit | A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0.openimageio · openimageio · CWE-122 | Critical9.8 | — | 1.9% | Dec 22, 2022 |
40Plan | CVE-2022-41639No exploit | A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.openimageio · openimageio · CWE-122 | Critical9.8 | — | 1.8% | Dec 22, 2022 |
40Plan | CVE-2022-41838No exploit | A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2.openimageio · openimageio · CWE-122 | Critical9.8 | — | 1.8% | Dec 22, 2022 |
39Monitor | CVE-2022-41837No exploit | An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.openimageio · openimageio · CWE-562 | Critical9.8 | — | 1.6% | Dec 22, 2022 |
39Monitor | CVE-2022-38143No exploit | A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images.openimageio · openimageio · CWE-123 | Critical9.8 | — | 1.4% | Dec 22, 2022 |
39Monitor | CVE-2023-42299No exploit | Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of servicopenimageio · openimageio · CWE-120 | Critical9.8 | — | 1.3% | Nov 2, 2023 |
39Monitor | CVE-2024-55194No exploit | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.openimageio · openimageio · CWE-787 | Critical9.8 | — | 0.7% | Jan 23, 2025 |
39Monitor | CVE-2024-55192No exploit | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char consopenimageio · openimageio · CWE-787 | Critical9.8 | — | 0.6% | Jan 23, 2025 |
39Monitor | CVE-2024-55193No exploit | OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.openimageio · openimageio · CWE-476 | Critical9.8 | — | 0.5% | Jan 23, 2025 |
36Monitor | CVE-2022-41649No exploit | A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0.openimageio · openimageio · CWE-125 | Critical9.1 | — | 1.5% | Dec 22, 2022 |
35Monitor | CVE-2023-42295No exploit | An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_imopenimageio · openimageio · CWE-190 | High8.8 | — | 0.9% | Oct 23, 2023 |
35Monitor | CVE-2026-43908No exploit | OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoderopenimageio · openimageio · CWE-190 | High8.8 | — | 0.5% | May 14, 2026 |
35Monitor | CVE-2026-43909No exploit | OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoderopenimageio · openimageio · CWE-125 | High8.8 | — | 0.5% | May 14, 2026 |
34Monitor | CVE-2026-43906No exploit | OpenImageIO: HEIF Heap overflowopenimageio · openimageio · CWE-122 | High8.5 | — | 0.2% | May 14, 2026 |
33Monitor | CVE-2022-43599No exploit | Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.openimageio · openimageio · CWE-122 | High8.1 | — | 2.0% | Dec 22, 2022 |
33Monitor | CVE-2022-43602No exploit | Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.openimageio · openimageio · CWE-122 | High8.1 | — | 1.9% | Dec 22, 2022 |
33Monitor | CVE-2022-43597No exploit | Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.openimageio · openimageio · CWE-122 | High8.1 | — | 1.8% | Dec 22, 2022 |
33Monitor | CVE-2022-43598No exploit | Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.openimageio · openimageio · CWE-122 | High8.1 | — | 1.8% | Dec 22, 2022 |
33Monitor | CVE-2026-43907No exploit | OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR)openimageio · openimageio · CWE-190 | High8.3 | — | 0.5% | May 14, 2026 |
33Monitor | CVE-2026-63638No exploit | OpenImageIO: Cineon invalid bit depth heap out-of-bounds writeopenimageio · openimageio · CWE-787 | High8.3 | — | 0.4% | Sep 18, 2026 |
33Monitor | CVE-2026-43904No exploit | OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image widthopenimageio · openimageio · CWE-787 | High8.4 | — | 0.2% | May 14, 2026 |
33Monitor | CVE-2026-43903No exploit | OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release buildsopenimageio · openimageio · CWE-787 | High8.4 | — | 0.2% | May 14, 2026 |
32Monitor | CVE-2022-43601No exploit | Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.openimageio · openimageio · CWE-122 | High8.1 | — | 1.7% | Dec 22, 2022 |
32Monitor | CVE-2022-43600No exploit | Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.openimageio · openimageio · CWE-122 | High8.1 | — | 1.7% | Dec 22, 2022 |
32Monitor | CVE-2022-41981No exploit | A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0.openimageio · openimageio · CWE-121 | High8.1 | — | 1.0% | Dec 22, 2022 |
- CVE-2022-4179440Plan
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0.
CriticalCVSS 9.8No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4163940Plan
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.
CriticalCVSS 9.8No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4183840Plan
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
CriticalCVSS 9.8No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4183739Monitor
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.
CriticalCVSS 9.8No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-3814339Monitor
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images.
CriticalCVSS 9.8No exploitEPSS 1%openimageio · openimageioDec 22, 2022
- CVE-2023-4229939Monitor
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of servic
CriticalCVSS 9.8No exploitEPSS 1%openimageio · openimageioNov 2, 2023
- CVE-2024-5519439Monitor
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CriticalCVSS 9.8No exploitEPSS 1%openimageio · openimageioJan 23, 2025
- CVE-2024-5519239Monitor
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char cons
CriticalCVSS 9.8No exploitEPSS 1%openimageio · openimageioJan 23, 2025
- CVE-2024-5519339Monitor
OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
CriticalCVSS 9.8No exploitEPSS 1%openimageio · openimageioJan 23, 2025
- CVE-2022-4164936Monitor
A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0.
CriticalCVSS 9.1No exploitEPSS 1%openimageio · openimageioDec 22, 2022
- CVE-2023-4229535Monitor
An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_im
HighCVSS 8.8No exploitEPSS 1%openimageio · openimageioOct 23, 2023
- CVE-2026-4390835Monitor
OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoder
HighCVSS 8.8No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2026-4390935Monitor
OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoder
HighCVSS 8.8No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2026-4390634Monitor
OpenImageIO: HEIF Heap overflow
HighCVSS 8.5No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2022-4359933Monitor
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4360233Monitor
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4359733Monitor
Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4359833Monitor
Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2026-4390733Monitor
OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR)
HighCVSS 8.3No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2026-6363833Monitor
OpenImageIO: Cineon invalid bit depth heap out-of-bounds write
HighCVSS 8.3No exploitEPSS 0%openimageio · openimageioSep 18, 2026
- CVE-2026-4390433Monitor
OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image width
HighCVSS 8.4No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2026-4390333Monitor
OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release builds
HighCVSS 8.4No exploitEPSS 0%openimageio · openimageioMay 14, 2026
- CVE-2022-4360132Monitor
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4360032Monitor
Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2.
HighCVSS 8.1No exploitEPSS 2%openimageio · openimageioDec 22, 2022
- CVE-2022-4198132Monitor
A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0.
HighCVSS 8.1No exploitEPSS 1%openimageio · openimageioDec 22, 2022