In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
{ "cna_assigner": "mitre", "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34300.json" }
{ "cpe": "cpe:2.3:a:tinyexr_project:tinyexr:1.0.1:*:*:*:*:*:*:*", "extracted_events": [ { "introduced": "1.0.1" }, { "last_affected": "1.0.1" } ], "source": "CPE_STRING" }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-34300.json"