Cary Phillips
7 exploits
Active since Feb 2026
OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API
CVSS 8.8
OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)
CVSS 9.8
OpenEXR 3.3.0-3.3.6/3.4.0-3.4.4 - Memory Corruption
CVSS 6.5
OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
CVSS 7.5
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
CVSS 7.3
OpenEXR: integer overflow lead to OOB in HTJ2K decoder
CVSS 7.3
OpenEXR 3.3.0-3.3.6/3.4.0-3.4.4 - Memory Corruption
CVSS 6.5