strukturag libheif是strukturag的图像编解码库。 strukturag libheif 1.22.0之前版本存在安全漏洞,该漏洞源于整数溢出,安全检查可被绕过,允许特制的HEIF文件触发越界堆读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47247 | 7.5 HIGH | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel |
| CVE-2026-45382 | 6.9 MEDIUM | libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS ti |
| CVE-2026-47178 | 6.1 MEDIUM | libheif has Heap Out Of Bounds Write in unci subsystem |
| CVE-2026-47254 | 6.1 MEDIUM | libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vecto |
| CVE-2026-47714 | 6.1 MEDIUM | libheif has integer overflow in inline mask size calculation that causes undersized buffer |
| CVE-2026-45383 | libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bound | |
| CVE-2026-47709 | libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed |
No comments yet