Tinyexr Project maintains a compact, single-purpose image-parsing library widely embedded in graphics, rendering, and multimedia applications, where its disclosures carry outsized risk due to the library's deep position in software supply chains. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety and input-validation weaknesses—out-of-bounds reads, improper array indexing, reachable assertions, and unbounded resource allocation—that are characteristic of native image decoders processing untrusted file data. Defenders should prioritize inventory of products that bundle this library and track upstream patches closely, since a single flaw can propagate broadly to downstream consumers; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinyexr Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12688CRITICAL tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. | Jun 22, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-12064CRITICAL tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h. | Jun 8, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12503CRITICAL tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h. | Jun 16, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-12092CRITICAL tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. | Jun 11, 2018 | 9.8 | 28 | NO | NO |
CVE-2022-34300HIGH In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. | Jun 23, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-38529HIGH tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress. | Sep 6, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-18430HIGH tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS). | Jul 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-18428HIGH tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS). | Jul 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-12687HIGH tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. | Jun 22, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-12504HIGH tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h. | Jun 16, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinyexr Project.
Media articles that mention a CVE ID that affects a product developed by Tinyexr Project — matched by CVE ID, not by vendor name.