VYPR

Vendor CVEs

Strukturag

All CVEs

114 total · sorted by risk
  • CVE-2023-51792LowApr 19, 2024
    risk 0.21cvss 3.3epss 0.00

    Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

  • CVE-2026-84448MedSep 18, 2026
    risk 0.19cvss 4.0epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and…

  • CVE-2026-84449LowSep 18, 2026
    risk 0.17cvss 3.7epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane().…

  • CVE-2025-61147MedFeb 23, 2026
    risk 0.00cvss 6.2epss 0.00

    strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

  • CVE-2025-68431MedDec 29, 2025
    risk 0.00cvss 6.5epss 0.00

    libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped…

  • CVE-2025-43967LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

  • CVE-2025-43966LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

  • CVE-2023-43887HigNov 22, 2023
    risk 0.00cvss 8.1epss 0.01

    Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.

  • CVE-2023-47471MedNov 16, 2023
    risk 0.00cvss 6.5epss 0.01

    Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component.

  • CVE-2023-0996HigFeb 24, 2023
    risk 0.00cvss 7.8epss 0.00

    There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

  • CVE-2022-1253CriApr 6, 2022
    risk 0.00cvss 9.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

  • CVE-2020-19499HigJul 21, 2021
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.

  • CVE-2020-19498HigJul 21, 2021
    risk 0.00cvss 8.8epss 0.01

    Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

  • CVE-2019-11471HigApr 23, 2019
    risk 0.00cvss 8.8epss 0.02

    libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

Page 3 of 3