VYPR

Libheif

by Strukturag

Source repositories

CVEs (48)

  • CVE-2026-84449LowSep 18, 2026
    risk 0.17cvss 3.7epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane().…

  • CVE-2025-68431MedDec 29, 2025
    risk 0.00cvss 6.5epss 0.00

    libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped…

  • CVE-2025-43967LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

  • CVE-2025-43966LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

  • CVE-2023-0996HigFeb 24, 2023
    risk 0.00cvss 7.8epss 0.00

    There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

  • CVE-2020-19499HigJul 21, 2021
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.

  • CVE-2020-19498HigJul 21, 2021
    risk 0.00cvss 8.8epss 0.01

    Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

  • CVE-2019-11471HigApr 23, 2019
    risk 0.00cvss 8.8epss 0.02

    libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

Page 3 of 3