strukturag libde265是strukturag公司的一个处理HEVC视频编码的库。 strukturag libde265 1.0.19之前版本存在缓冲区错误漏洞,该漏洞源于在 函数中存在堆缓冲区溢出(越界读取),当PPS/SPS头部被特制时可能导致堆缓冲区溢出。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libde265 | < 1.0.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libde265 | < 1.0.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47247 | 7.5 HIGH | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel |
| CVE-2026-45382 | 6.9 MEDIUM | libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS ti |
| CVE-2026-47178 | 6.1 MEDIUM | libheif has Heap Out Of Bounds Write in unci subsystem |
| CVE-2026-47254 | 6.1 MEDIUM | libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vecto |
| CVE-2026-47714 | 6.1 MEDIUM | libheif has integer overflow in inline mask size calculation that causes undersized buffer |
| CVE-2026-47709 | libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed | |
| CVE-2026-47251 | libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_dat |
No comments yet