strukturag libheif是strukturag的图像编解码库。 strukturag libheif 1.22.0之前版本存在数字错误漏洞,该漏洞源于libheif/region.cc中内联遮罩解析代码存在整数溢出,导致缓冲区分配不足,造成越界内存访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47247 | 7.5 HIGH | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel |
| CVE-2026-45382 | 6.9 MEDIUM | libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS ti |
| CVE-2026-47178 | 6.1 MEDIUM | libheif has Heap Out Of Bounds Write in unci subsystem |
| CVE-2026-47254 | 6.1 MEDIUM | libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vecto |
| CVE-2026-45383 | libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bound | |
| CVE-2026-47709 | libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed | |
| CVE-2026-47251 | libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_dat |
No comments yet