Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AcademySoftwareFoundation — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting AcademySoftwareFoundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Academy Software Foundation serves as a neutral home for open-source projects supporting the visual effects, animation, and media industries. Its portfolio includes critical tools like OpenColorIO and OpenUSD, which facilitate data interchange and rendering workflows across major studios. Historically, vulnerabilities within these ecosystems have predominantly involved remote code execution and cross-site scripting, often stemming from complex input parsing in image processing libraries. While the foundation itself does not develop software, it oversees governance for member projects, meaning security incidents typically reflect the underlying codebases rather than the foundation’s infrastructure. Notable incidents have included privilege escalation flaws in plugin architectures, highlighting risks in extensible systems. With 27 recorded CVEs, the foundation emphasizes collaborative security audits and standardized testing protocols to mitigate risks inherent in high-precision visual computing environments, ensuring stability for global production pipelines without adopting aggressive marketing narratives.

Found 10 results / 41 Clear Filters
Top products by AcademySoftwareFoundation: openexr OpenImageIO MaterialX OpenColorIO
CVE ID Title CVSS Severity Published
CVE-2026-43903 OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops in release builds — OpenImageIO CWE-787 - - 2026-05-14
CVE-2026-43904 OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to image width — OpenImageIO CWE-787 - - 2026-05-14
CVE-2026-43905 OpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocation — OpenImageIO CWE-190 - - 2026-05-14
CVE-2026-43996 OpenImageIO: Integer wraparound in bounds check of decode_pixel leads to out-of-bounds read in TGA paletted image decoder — OpenImageIO CWE-125 5.5 Medium 2026-05-14
CVE-2026-43907 OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR) — OpenImageIO CWE-190 8.3 High 2026-05-14
CVE-2026-43908 OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoder — OpenImageIO CWE-190 8.8 High 2026-05-14
CVE-2026-43909 OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoder — OpenImageIO CWE-125 8.8 High 2026-05-14
CVE-2026-43906 OpenImageIO: HEIF Heap overflow — OpenImageIO CWE-122 - - 2026-05-14
CVE-2026-7582 AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write — OpenImageIO CWE-787 5.3 Medium 2026-05-01
CVE-2024-40630 HEIF Heap OOB Read in OpenImageIO — OpenImageIO CWE-125 4.3 Medium 2024-07-15

This page lists every published CVE security advisory associated with AcademySoftwareFoundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.