VYPR

Libde265

by Strukturag

Source repositories

CVEs (67)

  • CVE-2026-33165MedMar 20, 2026
    risk 0.29cvss 5.5epss 0.00

    libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and…

  • CVE-2026-49337MedJun 19, 2026
    risk 0.21cvss 4.3epss 0.00

    libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image…

  • CVE-2023-51792LowApr 19, 2024
    risk 0.21cvss 3.3epss 0.00

    Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

  • CVE-2025-61147MedFeb 23, 2026
    risk 0.00cvss 6.2epss 0.00

    strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

  • CVE-2023-43887HigNov 22, 2023
    risk 0.00cvss 8.1epss 0.01

    Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.

  • CVE-2023-47471MedNov 16, 2023
    risk 0.00cvss 6.5epss 0.01

    Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component.

  • CVE-2022-1253CriApr 6, 2022
    risk 0.00cvss 9.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

Page 4 of 4