These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The OpenEXR library, widely used in the motion picture industry for handling EXR image files, contains a vulnerability in its exrmultiview utility. This utility can write past a heap allocation when combining two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The vulnerability is triggered by normal public-tool processing a [truncated]
A heap out-of-bounds write vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, specifically in the PyOpenEXR Python bindings. This issue is triggered when reading a crafted deep scanline EXR file, leading to memory corruption and a crash. The vulnerability is fixed in versions 3.3.13 and 3.4.14. Defenders responsible for systems using OpenEXR, particularly in the motion [truncated]
A heap buffer overflow vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, specifically in PyOpenEXR when handling a crafted flat scanline EXR file with a channel-name key collision between literal and prefixed RGB channels. This vulnerability can lead to potential arbitrary code execution, emphasizing the need for verification of exposure and prioritization of updates [truncated]
CVE-2026-59981 is a vulnerability in the OpenEXR library, which is used for reading and writing EXR image files. The vulnerability occurs when a deep image has a non-zero dataWindow origin, causing the SampleCountChannel::row() API to return an out-of-bounds pointer. This can lead to an out-of-bounds read, potentially crashing the process or returning adjacent heap memory as sample-count values.
CVE-2026-65979 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability exists in versions 3.4.0 through 3.4.12 and allows for an out-of-bounds read when decoding an untrusted file. This issue is fixed in version 3.4.13. The vulnerability is caused by the HTJ2K decoder parsing a header-length field from a chunk's compressed data without checking if it fit [truncated]
CVE-2026-62986 is a vulnerability in OpenEXR, a widely used image file format in the motion picture industry. The issue affects versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, where the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR file. This can lead to exposure of uninitialized same-process heap contents and incorrect green and blue channel data when p [truncated]
CVE-2026-59985 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format. A heap out-of-bounds read issue exists in OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 on ILP32 builds. This issue can cause denial of service when a crafted RLE-compressed EXR file is processed. The vulnerability is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-59984 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format. A crafted B44-compressed scanline EXR can cause an out-of-bounds write, leading to denial of service and memory corruption on ILP32 builds of OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-59983 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format widely used in the motion picture industry. A crafted uncompressed deep-tile EXR can cause an out-of-bounds read, leading to denial of service on ILP32 builds. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. The vulnerability is caused by an out-of-bounds read when decoding a cra [truncated]
CVE-2026-59982 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted deep EXR image can cause an out-of-bounds pointer return, potentially leading to a crash or limited information disclosure. The issue is fixed in OpenEXR versions 3.2.11, 3.3.13, and 3.4.14. This vulnerability affects systems and applications using OpenEXR, particularly in the motion picture [truncated]
CVE-2026-59189 is a heap out-of-bounds read vulnerability in OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12. The vulnerability arises from the TypedDeepImageChannel<T>::row() API returning an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a crash and potential information disclosure. This issue is fixed in versions 3.3.13 and 3.4.13.
A heap out-of-bounds write vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 when processing crafted deep scanline EXR images with specific pixel conversion options. This issue is fixed in versions 3.3.13 and 3.4.14. The vulnerability can lead to data corruption or crashes, and defenders in the motion picture industry or other environments using OpenEXR should assess e [truncated]
CVE-2026-59186 is a heap out-of-bounds write vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability affects versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. A crafted tiled EXR image can trigger the vulnerability when read through the public TiledRgbaInputFile RGBA API on 32-bit/ILP32 builds. The issue is fixed in versions 3.2.11, 3.3. [truncated]
CVE-2026-59184 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted EXR file can cause out-of-bounds or use-after-free writes when processed by certain applications. This issue is fixed in OpenEXR versions 3.2.11, 3.3.13, and 3.4.14. The vulnerability occurs when a crafted EXR file with a nonzero dataWindow.min is processed, causing out-of-bounds or use-after [truncated]
A vulnerability in OpenEXR, a widely used image format in the motion picture industry, can cause a crash when decoding crafted deep tiled EXR files. The issue arises from an int32_t multiplication overflow in the unpack_sample_table() function, leading to an invalid pointer and a read from an unmapped memory address. This affects applications that decode deep tiled EXR files. Fixes are available in versio [truncated]
CVE-2026-55373 is a medium-severity vulnerability affecting OpenEXR, a widely used image format in the motion picture industry. The issue, caused by an infinite-loop vulnerability in SampleCountChannel, can be triggered through public OpenEXRUtil APIs. This vulnerability has been fixed in OpenEXR versions 3.2.10, 3.3.12, and 3.4.13. Affected product deployments should be assessed for exposure, and defende [truncated]
A NULL pointer dereference vulnerability exists in OpenEXR versions 3.4.0 through 3.4.12. The issue is fixed in version 3.4.13. This vulnerability results in a denial of service. Defenders should assess exposure and prioritize verification and mitigation for systems and software using OpenEXR, focusing on version upgrades and compensating controls. The vulnerability is caused by a NULL pointer dereference [truncated]
A heap out-of-bounds write vulnerability exists in OpenEXR versions prior to 3.2.10, 3.3.12, and 3.4.13. This issue is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. The vulnerability is caused by a row-based sample-count setter computing the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y.
CVE-2026-54920 is a denial-of-service vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted HTJ2K-compressed EXR file can cause an unconditional process abort in applications that call exr_start_read() on untrusted input. This issue has been resolved in version 3.4.13. The vulnerability is triggered by a QCD marker whose lower five bits are zero, which OpenEXR pass [truncated]
CVE-2026-53532 is a denial-of-service vulnerability affecting OpenEXR versions 3.4.0 through 3.4.12. A crafted HTJ2K-compressed EXR file can cause an unconditional process abort when processed by applications calling exr_start_read() on untrusted input. This issue has been resolved in version 3.4.13. The vulnerability is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into t [truncated]
CVE-2026-68516 is a denial-of-service vulnerability affecting OpenEXR versions 3.4.0 through 3.4.13. A crafted HTJ2K-compressed EXR image can cause a stack out-of-bounds write during normal decode, leading to a crash. This issue is fixed in OpenEXR version 3.4.14. The vulnerability is particularly concerning for the motion picture industry, which heavily utilizes the EXR image format. Defenders should ass [truncated]
CVE-2026-45696 is a high-severity vulnerability in OpenEXR, a widely-used image format in the motion picture industry. A heap-buffer-overflow READ vulnerability exists in the HTJ2K decoder, ht_undo_impl() in OpenEXRCore, affecting versions 3.4.0 through 3.4.11. The vulnerability occurs when the ht_undo_impl function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared wi [truncated]
CVE-2026-44663 is a heap-buffer overflow vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability exists in the ht_undo_impl() function in src/lib/OpenEXRCore/internal_ht.cpp, where an integer overflow occurs when decoding a crafted HTJ2K-compressed EXR file. This leads to a corrupted offset used for pointer arithmetic, causing a heap out-of-bounds write. The [truncated]
CVE-2026-42216 is a high-severity vulnerability in OpenEXR, an image storage format for the motion picture industry. The vulnerability affects versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The issue arises from the IDManifest::init() function, which reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next [truncated]
CVE-2026-41142 is an integer overflow vulnerability in the OpenEXR image storage format, specifically in the ImageChannel::resize function. This issue affects OpenEXR versions from 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The vulnerability leads to a heap out-of-bounds write via the OpenEXRUtil public API, posing a significant risk to applications utilizing OpenEXR. The C [truncated]
CVE-2026-40244 is a high-severity vulnerability in OpenEXR, an image storage format used in the motion picture industry. The vulnerability affects OpenEXR versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7. The issue is caused by an integer overflow in the `internal_dwa_compressor.h` file, which can lead to potential code execution. The vulnerability has a CVSS score of 8.4 and is [truncated]