Lucene search

K
osvGoogleOSV:CVE-2021-26260
HistoryJun 08, 2021 - 12:15 p.m.

CVE-2021-26260

2021-06-0812:15:10
Google
osv.dev
12
openexr
integer overflow
heap-buffer overflow

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

33.5%

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.