Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

strukturag — Vulnerabilities & Security Advisories 43

Browse all 43 CVE security advisories affecting strukturag. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Strukturag develops enterprise software solutions for document management and workflow automation, primarily serving government and financial sectors. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and access control flaws. Six CVEs have been recorded, with several allowing attackers to execute arbitrary code or bypass authentication. While no major public security incidents have been documented, the consistent pattern of vulnerabilities in core functionality suggests ongoing challenges in secure coding practices, particularly in handling user inputs and implementing proper session management.

CVE ID Title CVSS Severity Published
CVE-2026-84450 libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289) — libheif CWE-617 4.3 Medium 2026-09-18
CVE-2026-84449 libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV — libheif CWE-190 3.7 Low 2026-09-18
CVE-2026-84451 libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read — libheif CWE-125 6.5 Medium 2026-09-18
CVE-2026-84447 libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS — libheif CWE-770 7.5 High 2026-09-18
CVE-2026-84384 libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS — libheif CWE-409 7.5 High 2026-09-18
CVE-2026-84444 libheif uncompressed tiled image encoding allows out-of-bounds write — libheif CWE-787 7.4 High 2026-09-18
CVE-2026-84383 libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items — libheif CWE-787 9.8 Critical 2026-09-18
CVE-2026-84446 libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames — libheif CWE-835 7.5 High 2026-09-18
CVE-2026-84448 libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image) — libheif CWE-125 4.0 Medium 2026-09-18
CVE-2026-54241 libde265: SAO sequential filter heap buffer overflow via signed integer overflow — libde265 CWE-122 7.4 High 2026-09-11
CVE-2026-54240 libde265: Pixel accessor signed integer overflow causes heap OOB read/write — libde265 CWE-190 7.4 High 2026-09-11
CVE-2026-62377 libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110) — libheif CWE-617 4.3 Medium 2026-08-18
CVE-2026-62291 libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions — libheif CWE-125 5.3 Medium 2026-08-18
CVE-2026-62292 libheif: Out-of-bounds read in uncompressed unci tile range slicing — libheif CWE-125 8.7 High 2026-08-18
CVE-2026-62289 libheif: Integer underflow in Fraction constructor via double clap transform application — libheif CWE-191 4.3 Medium 2026-08-18
CVE-2026-50142 libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check) — libheif CWE-190 7.5 High 2026-08-18
CVE-2026-48029 libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow — libheif CWE-125 7.1 High 2026-07-22
CVE-2026-47709 libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe — libheif CWE-476 - - 2026-07-21
CVE-2026-47254 libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access — libheif CWE-125 6.1 Medium 2026-07-21
CVE-2026-47251 libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2 — libheif CWE-125 - - 2026-07-21
CVE-2026-47247 libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation — libheif CWE-200 7.5 High 2026-07-21
CVE-2026-47178 libheif has Heap Out Of Bounds Write in unci subsystem — libheif CWE-787 6.1 Medium 2026-07-21
CVE-2026-47714 libheif has integer overflow in inline mask size calculation that causes undersized buffer allocation — libheif CWE-190 6.1 Medium 2026-07-21
CVE-2026-45383 libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18 — libde265 CWE-125 - - 2026-07-21
CVE-2026-45382 libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry — libde265 CWE-125 6.9 Medium 2026-07-21
CVE-2026-49346 libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow — libde265 CWE-190 7.1 High 2026-06-19
CVE-2026-49295 libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS — libde265 CWE-787 7.1 High 2026-06-19
CVE-2026-49337 libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL` — libde265 CWE-770 4.3 Medium 2026-06-19
CVE-2026-49271 libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder — libheif CWE-125 6.5 Medium 2026-06-19
CVE-2026-41071 libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count — libheif CWE-125 - - 2026-05-22

This page lists every published CVE security advisory associated with strukturag. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.