Lucene search

K

Struktur Security Vulnerabilities

cve
cve

CVE-2019-11471

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

8.8CVSS

8.5AI Score

0.003EPSS

2019-04-23 02:29 PM
53
cve
cve

CVE-2020-19498

Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

8.8CVSS

8.7AI Score

0.002EPSS

2021-07-21 06:15 PM
27
2
cve
cve

CVE-2020-19499

An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.

8.8CVSS

8.7AI Score

0.002EPSS

2021-07-21 06:15 PM
23
cve
cve

CVE-2020-21594

libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
68
cve
cve

CVE-2020-21595

libde265 v1.0.4 contains a heap buffer overflow in the mc_luma function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
61
2
cve
cve

CVE-2020-21596

libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.002EPSS

2021-09-16 10:15 PM
73
4
cve
cve

CVE-2020-21597

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.003EPSS

2021-09-16 10:15 PM
76
2
cve
cve

CVE-2020-21598

libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.

8.8CVSS

8.5AI Score

0.004EPSS

2021-09-16 10:15 PM
75
cve
cve

CVE-2020-21599

libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
75
2
cve
cve

CVE-2020-21600

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
69
cve
cve

CVE-2020-21601

libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
63
cve
cve

CVE-2020-21602

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
73
2
cve
cve

CVE-2020-21603

libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
64
2
cve
cve

CVE-2020-21604

libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
64
cve
cve

CVE-2020-21605

libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.

6.5CVSS

6.9AI Score

0.001EPSS

2021-09-16 10:15 PM
55
cve
cve

CVE-2020-21606

libde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_16_fallback function, which can be exploited via a crafted a file.

6.5CVSS

7.2AI Score

0.001EPSS

2021-09-16 10:15 PM
55
2
cve
cve

CVE-2020-23109

Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

8.1CVSS

7.7AI Score

0.002EPSS

2021-11-03 05:15 PM
22
cve
cve

CVE-2021-35452

An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.

6.5CVSS

6.3AI Score

0.001EPSS

2022-01-10 10:15 PM
68
cve
cve

CVE-2021-36408

An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.

5.5CVSS

5.5AI Score

0.001EPSS

2022-01-10 11:15 PM
75
cve
cve

CVE-2021-36409

There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.

7.8CVSS

7.9AI Score

0.001EPSS

2022-01-10 11:15 PM
46
cve
cve

CVE-2021-36410

A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.

5.5CVSS

5.5AI Score

0.001EPSS

2022-01-10 11:15 PM
73
cve
cve

CVE-2021-36411

An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

5.5CVSS

5.5AI Score

0.001EPSS

2022-01-10 11:15 PM
68
cve
cve

CVE-2022-1253

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

9.8CVSS

9.3AI Score

0.003EPSS

2022-04-06 12:15 PM
90
cve
cve

CVE-2022-43235

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
32
6
cve
cve

CVE-2022-43236

Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
72
6
cve
cve

CVE-2022-43237

Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
67
6
cve
cve

CVE-2022-43238

Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
56
4
cve
cve

CVE-2022-43239

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma<unsigned short> in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
64
6
cve
cve

CVE-2022-43240

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
58
6
cve
cve

CVE-2022-43241

Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
60
8
cve
cve

CVE-2022-43242

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma<unsigned char> in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
61
6
cve
cve

CVE-2022-43243

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weighted_pred_avg_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
68
6
cve
cve

CVE-2022-43244

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 02:15 PM
62
6
cve
cve

CVE-2022-43245

Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned short> in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 02:15 PM
60
8
cve
cve

CVE-2022-43248

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
61
8
cve
cve

CVE-2022-43249

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 02:15 PM
56
6
cve
cve

CVE-2022-43250

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

6.4AI Score

0.001EPSS

2022-11-02 02:15 PM
58
6
cve
cve

CVE-2022-43252

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
57
4
cve
cve

CVE-2022-43253

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.

6.5CVSS

7.3AI Score

0.001EPSS

2022-11-02 02:15 PM
67
4
cve
cve

CVE-2022-47655

Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>

7.8CVSS

7.3AI Score

0.001EPSS

2023-01-05 04:15 PM
62
cve
cve

CVE-2022-47664

Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse

7.8CVSS

7.3AI Score

0.001EPSS

2023-03-03 03:15 PM
24
cve
cve

CVE-2022-47665

Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)

7.8CVSS

7.6AI Score

0.001EPSS

2023-03-03 03:15 PM
34
cve
cve

CVE-2023-0996

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

7.8CVSS

7.6AI Score

0.002EPSS

2023-02-24 04:15 AM
20
cve
cve

CVE-2023-24751

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

6.5CVSS

6AI Score

0.001EPSS

2023-03-01 03:15 PM
32
cve
cve

CVE-2023-24752

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
31
cve
cve

CVE-2023-24754

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
30
cve
cve

CVE-2023-24755

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
28
cve
cve

CVE-2023-24756

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
26
cve
cve

CVE-2023-24757

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
27
cve
cve

CVE-2023-24758

libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

5.5CVSS

5.4AI Score

0.0005EPSS

2023-03-01 03:15 PM
29
Total number of security vulnerabilities63