Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AcademySoftwareFoundation — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting AcademySoftwareFoundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Academy Software Foundation serves as a neutral home for open-source projects supporting the visual effects, animation, and media industries. Its portfolio includes critical tools like OpenColorIO and OpenUSD, which facilitate data interchange and rendering workflows across major studios. Historically, vulnerabilities within these ecosystems have predominantly involved remote code execution and cross-site scripting, often stemming from complex input parsing in image processing libraries. While the foundation itself does not develop software, it oversees governance for member projects, meaning security incidents typically reflect the underlying codebases rather than the foundation’s infrastructure. Notable incidents have included privilege escalation flaws in plugin architectures, highlighting risks in extensible systems. With 27 recorded CVEs, the foundation emphasizes collaborative security audits and standardized testing protocols to mitigate risks inherent in high-precision visual computing environments, ensuring stability for global production pipelines without adopting aggressive marketing narratives.

Top products by AcademySoftwareFoundation: openexr OpenImageIO MaterialX OpenColorIO
HighCVE-2020-45062026-06-19
OpenEXR ht_undo_impl heap-buffer-overflow READ via codestream/channel width mismatch in HTJ2K decode · Advisory · Academ
Medium2026-06-19
Integer overflow in HTJ2K decoder ( ht_undo_impl ) leading to heap-buffer-overflow · Advisory · AcademySoftwareFoundatio
High2026-05-22
Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR) · Adv
HighCVE-2026-43062026-05-22
HEIF Heap overflow · Advisory · AcademySoftwareFoundation/OpenImageIO · GitHub
HighCVE-2024-439052026-05-22
JPEG2000 (OpenJPH) signed integer overflow in buffer allocation · Advisory · AcademySoftwareFoundation/OpenImageIO · Git
High2026-04-21
Integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589) · Advisory ·
HighCVE-2020-345882026-04-07
Signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write · Advisory · AcademySoftwareFoundation/openexr · GitHub
High2026-04-07
Signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x · Advisory · A
Unknown2026-04-02
Release v3.4.8 · AcademySoftwareFoundation/openexr · GitHub
Critical2026-04-02
integer overflow to OOB write in uncompress_b44_impl() · Advisory · AcademySoftwareFoundation/openexr · GitHub
High2026-04-02
Release v3.4.7 · AcademySoftwareFoundation/openexr · GitHub
Unknown2025-11-20
OpenImageIO/src/heif.imageio/heifinput.cpp at 7c486a1121a4bf71d50ff555fab2770294b748d7 · AcademySoftwareFoundation/OpenI
LowCVE-2025-530102025-08-03
Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return · Advisory · AcademySoftwareFoun
LowCVE-2025-480732025-08-02
ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode · Advisory · AcademySoftwareFoundation/openexr · Git

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with AcademySoftwareFoundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.