Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AcademySoftwareFoundation — Vulnerabilities & Security Advisories 63

Browse all 63 CVE security advisories affecting AcademySoftwareFoundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Academy Software Foundation serves as a neutral home for open-source projects supporting the visual effects, animation, and media industries. Its portfolio includes critical tools like OpenColorIO and OpenUSD, which facilitate data interchange and rendering workflows across major studios. Historically, vulnerabilities within these ecosystems have predominantly involved remote code execution and cross-site scripting, often stemming from complex input parsing in image processing libraries. While the foundation itself does not develop software, it oversees governance for member projects, meaning security incidents typically reflect the underlying codebases rather than the foundation’s infrastructure. Notable incidents have included privilege escalation flaws in plugin architectures, highlighting risks in extensible systems. With 27 recorded CVEs, the foundation emphasizes collaborative security audits and standardized testing protocols to mitigate risks inherent in high-precision visual computing environments, ensuring stability for global production pipelines without adopting aggressive marketing narratives.

Top products by AcademySoftwareFoundation: openexr OpenImageIO MaterialX OpenColorIO
CVE ID Title CVSS Severity Published
CVE-2026-59981 OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow — openexr CWE-125 7.1 High 2026-08-25
CVE-2026-68514 OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep images — openexr CWE-122 5.5 Medium 2026-08-25
CVE-2026-68515 OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union — openexr CWE-122 7.1 High 2026-08-25
CVE-2026-68513 OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision — openexr CWE-122 7.1 High 2026-08-25
CVE-2026-65979 OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) — openexr CWE-20 6.7 Medium 2026-08-25
CVE-2026-62986 OpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosure — openexr CWE-200 4.3 Medium 2026-08-25
CVE-2026-61555 OpenEXR: Empty multiView viewFromChannelName file crash — openexr CWE-125 5.5 Medium 2026-08-25
CVE-2026-59985 OpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32 — openexr CWE-125 5.5 Medium 2026-08-25
CVE-2026-59984 OpenEXR: Scratch buffer overflow decoding B44-compressed InputFile on ILP32 — openexr CWE-787 5.5 Medium 2026-08-25
CVE-2026-59983 OpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode on ILP32 — openexr CWE-125 5.5 Medium 2026-08-25
CVE-2026-59982 OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms — openexr CWE-190 7.1 High 2026-08-25
CVE-2026-59189 OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow origin — openexr CWE-125 7.1 High 2026-08-25
CVE-2026-59187 OpenEXR: exrmetrics deep pixelmode heap buffer overflow — openexr CWE-122 7.1 High 2026-08-25
CVE-2026-59186 OpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow on 32-bit (ILP32) builds — openexr CWE-122 7.1 High 2026-08-25
CVE-2026-59184 OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write — openexr CWE-416 7.1 High 2026-08-25
CVE-2026-59183 OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding — openexr CWE-190 5.5 Medium 2026-08-25
CVE-2026-55373 OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample counts — openexr CWE-190 6.2 Medium 2026-08-25
CVE-2026-55371 OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length — openexr CWE-20 6.9 Medium 2026-08-25
CVE-2026-55059 OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerability — openexr CWE-787 6.1 Medium 2026-08-25
CVE-2026-54920 OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize — openexr CWE-190 - - 2026-08-25
CVE-2026-53532 OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) — openexr CWE-617 7.1 High 2026-08-24
CVE-2026-68516 OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow — openexr CWE-787 6.5 Medium 2026-08-24
CVE-2026-42450 OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser — OpenColorIO CWE-120 - - 2026-06-24
CVE-2026-45696 OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) — openexr CWE-122 - - 2026-06-18
CVE-2026-44663 OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow — openexr CWE-190 6.1 Medium 2026-06-18
CVE-2026-43903 OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release builds — OpenImageIO CWE-787 - - 2026-05-14
CVE-2026-43904 OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image width — OpenImageIO CWE-787 - - 2026-05-14
CVE-2026-43905 OpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocation — OpenImageIO CWE-190 - - 2026-05-14
CVE-2026-43996 OpenImageIO: Integer wraparound in bounds check of decode_pixel leads to out-of-bounds read in TGA paletted image decoder — OpenImageIO CWE-125 5.5 Medium 2026-05-14
CVE-2026-43907 OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR) — OpenImageIO CWE-190 8.3 High 2026-05-14

This page lists every published CVE security advisory associated with AcademySoftwareFoundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.