Openimageio

Vendor:

First CVE: Dec 22, 2022 · Active for 3 years

42
Total CVEs
More Total CVEs than 97% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openimageio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2022
3 years ago
Most Recent CVE
May 14, 2026
72 days ago

CVE Severity & Scoring

Openimageio42 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local8 (19.0%)
Network34 (81.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (69.0%)
High13 (31.0%)
Unknown0 (0.0%)
User Interaction
None30 (71.4%)
Unknown0 (0.0%)
Required12 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None42 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in
May 14, 20268.833NONO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit in
May 14, 20268.832NONO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer o
May 14, 20268.331NONO
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer over
Dec 22, 20229.831NONO
An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can
Dec 22, 20229.831NONO
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can
Dec 22, 20229.831NONO
A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds
Dec 22, 20229.831NONO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,2
May 14, 20267.830NONO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp
May 14, 20267.830NONO
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffe
May 14, 20267.830NONO

Exploit Exposure

Signals from CVEs in this product scope (42 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (42 CVEs).

Media Mentions

Signals from CVEs in this product scope (42 CVEs).

Top CNAs Publishing CVEs For Openimageio

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.0.257.80.3%00
3.2.0.037.70.3%00
3.1.0.039.80.6%00
2.4.7.137.51.1%00
2.4.4.2157.41.5%00
2.4.12.029.31.1%00
2.4.1117.51.2%00
2.3.19.097.81.3%00
2022-09-1415.50.8%00