Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28166
HistoryDec 06, 2020 - 3:19 a.m.

Arbitrary Code Execution

2020-12-0603:19:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
openexr
software vulnerability
arbitrary code execution
invalid write
host os
crash
application.

EPSS

0.016

Percentile

87.6%

openexr is vulnerable to arbitrary code execution. An invalid write of size 2 in the = operator function in half.h could allow an attacker to crash the application or execute arbitrary code on the host OS.