VendorsStrukturlibheifany version
Vulnerabilities

Struktur Libheif any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-32740
libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing
Published 2026-05-19 · Modified
8.8EPSS 0.006
CVE-2026-41071
libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count
Published 2026-05-22 · Analyzed
8.1EPSS 0.004
CVE-2026-47178
libheif has Heap Out Of Bounds Write in unci subsystem
Published 2026-07-21 · Analyzed
7.8EPSS 0.002
CVE-2024-25269
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
Published 2024-03-05 · Analyzed
7.5EPSS 0.007
CVE-2026-47247
libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
Published 2026-07-21 · Analyzed
7.5EPSS 0.005
CVE-2025-43967
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.
Published 2025-04-20 · Analyzed
7.5EPSS 0.004
CVE-2025-43966
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
Published 2025-04-20 · Analyzed
7.5EPSS 0.003
CVE-2026-48029
libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow
Published 2026-07-22 · Analyzed
7.1EPSS 0.004
CVE-2025-68431
libheif has Potential Heap Buffer Over-Read
Published 2025-12-29 · Analyzed
7.1EPSS 0.003
CVE-2026-47709
libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe
Published 2026-07-21 · Analyzed
6.9EPSS 0.002
CVE-2026-47251
libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2
Published 2026-07-21 · Analyzed
6.8EPSS 0.002
CVE-2026-41069
libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
Published 2026-05-22 · Analyzed
6.5EPSS 0.004
CVE-2026-32739
libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookup
Published 2026-05-19 · Analyzed
6.5EPSS 0.004
CVE-2026-32738
libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk
Published 2026-05-19 · Analyzed
6.5EPSS 0.004
CVE-2026-49271
libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder
Published 2026-06-19 · Analyzed
6.5EPSS 0.004
CVE-2026-47254
libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access
Published 2026-07-21 · Analyzed
6.1EPSS 0.002
CVE-2026-47714
libheif has integer overflow in inline mask size calculation that causes undersized buffer allocation
Published 2026-07-21 · Analyzed
6.1EPSS 0.002