Skip to main content

Threats Tagged 'cve-2026-55373'

View all threats tagged with 'cve-2026-55373'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-55373

Threats Tagged 'cve-2026-55373'

Click on any threat for detailed analysis and mitigation recommendations

OpenEXR versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an integer overflow vulnerability in the SampleCountChannel component. This flaw causes an infinite loop when the sample-list size is rounded up to the next power of two, due to a 32-bit unsigned integer wraparound. The issue can be triggered via public APIs by setting a pixel's sample count to UINT_MAX. The vulnerability has been fixed in versions 3.2.10, 3.3.12, and 3.4.13.

Join the discussion

A reachable assertion vulnerability in AcademySoftwareFoundation's openexr versions 3.4.0 through 3.4.12 allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort when exr_start_read() is called on untrusted input. This results in a denial of service. The issue arises from an assertion failure in the OpenJPH library triggered by a QCD marker with invalid bits. The vulnerability is fixed in version 3.4.13.

Join the discussion
0

This security update for OpenEXR addresses three vulnerabilities: an unchecked integer overflow in Image::resize() that can cause invalid memory deletion, a heap out-of-bounds write due to incorrect use of dataWindow coordinates, and an integer overflow in roundListSizeUp() that may cause an infinite loop. These issues could lead to memory corruption or denial of service. The vulnerabilities have been assigned CVE identifiers CVE-2026-54920, CVE-2026-55059, and CVE-2026-55373. No specific affected versions or patch details are provided in the available data.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2026-55373
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses