Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-48029 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile v… Libheif 1.22.0+ Fix from $1,9502026-07-22 MEDIUM 5.5 CVE-2026-47709 libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling(… Libheif 1.22.0+ Fix from $1,6002026-07-21 HIGH 7.8 CVE-2026-47178 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled,… Libheif 1.22.0+ Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-47247 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible… Libheif 1.22.0+ Fix from $1,9502026-07-21 MEDIUM 6.1 CVE-2026-47251 libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in … Libheif 1.22.0+ Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-47254 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.… Libheif 1.22.0+ Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-47714 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contain… Libheif 1.22.0+ Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-49295 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds arr… Libde265 1.0.20+ Fix from $1,9502026-06-19 HIGH 7.1 CVE-2026-49346 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 1… Libde265 1.1.0+ Fix from $1,9502026-06-19 MEDIUM 6.5 CVE-2026-49271 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed… Libheif 1.22.1+ Fix from $1,6002026-06-19 HIGH 8.1 CVE-2026-41071 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares mo… Libheif 1.22.0+ Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-41069 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds… Libheif 1.22.0+ Fix from $1,6002026-05-22 HIGH 8.8 CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the gri… Libheif 1.22.0+ Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-32739 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite lo… Libheif 1.22.0+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-32738 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chun… Libheif 1.22.0+ Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-33164 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fau… Libde265 1.0.17+ Fix from $1,9502026-03-20 MEDIUM 5.0 CVE-2026-33165 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap wr… Libde265 1.0.17+ Fix from $1,6002026-03-20 MEDIUM 6.2 CVE-2025-61147 strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). Libde265 1.0.17+ Fix from $1,6002026-02-23 HIGH 7.1 CVE-2025-68431 libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path trigg… Libheif 1.21.0+ Fix from $1,9502025-12-29 HIGH 7.5 CVE-2025-43966 libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc. Libheif 1.19.6+ Fix from $1,9502025-04-21 HIGH 7.5 CVE-2025-43967 libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonex… Libheif 1.19.6+ Fix from $1,9502025-04-21 MEDIUM 6.2 CVE-2025-29482 Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of … Libheif No fix yet Fix from $1,6002025-04-07 MEDIUM 6.5 CVE-2024-38949 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at s… Libde265 Mitigation only Fix from $1,6002024-06-26 MEDIUM 6.5 CVE-2024-38950 Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. Libde265 No fix yet Fix from $1,6002024-06-26 HIGH 7.5 CVE-2024-25269 libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack. Libheif after 1.17.6 Fix from $1,9502024-03-05 HIGH 8.8 CVE-2023-49460 libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image. Libheif No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49462 libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc. Libheif Patch available Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49463 libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc. Libheif Patch available Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49464 libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuratio… Libheif Patch available Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49465 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. Libde265 Patch available Fix from $1,9502023-12-07