CVE-2023-42299: Openimageio

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.

Affected products

Published 2023-11-02. Last modified 2026-06-17.