struktur AG libheif是struktur AG组织的一款图像编解码库。 struktur AG libheif 1.23.0及之前版本存在安全漏洞,该漏洞源于处理clean aperture box时存在整数下溢问题,导致图像尺寸变为零,可能造成崩溃或平铺结果损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.23.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.23.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62292 | 8.7 HIGH | libheif: Out-of-bounds read in uncompressed unci tile range slicing |
| CVE-2026-50142 | 7.5 HIGH | libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing b |
| CVE-2026-62291 | 5.3 MEDIUM | libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with |
| CVE-2026-62377 | 4.3 MEDIUM | libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF |
No comments yet