Lucene search

K
cvelistRedhatCVELIST:CVE-2021-23169
HistoryJun 08, 2021 - 12:00 a.m.

CVE-2021-23169

2021-06-0800:00:00
CWE-787
redhat
www.cve.org
8
cve-2021-23169
openexr
buffer overflow
arbitrary code
user permissions

AI Score

9.1

Confidence

High

EPSS

0.004

Percentile

72.5%

A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "OpenEXR",
    "versions": [
      {
        "version": "OpenEXR 3.0.1",
        "status": "affected"
      }
    ]
  }
]

AI Score

9.1

Confidence

High

EPSS

0.004

Percentile

72.5%