See how struktur compares to other vendors in security performance
Last updated 10 July 2026
Last updated 10 July 2026
Last updated 29 June 2026
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.
libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit b97c8b5, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the same out-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a separate, currently-unpatched vulnerability. Issue #1712 was closed as fixed without testing the edge case where size is near UINT32MAX. Version 1.22.0 patches the issue.
Last updated 10 July 2026
Last updated 10 July 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in de265imagegetbuffer() (libde265/image.cc:128). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent fillimage() call computes the real size using sizet, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.
Last updated 17 July 2026
Last updated 29 June 2026
Last updated 10 July 2026
Last updated 27 February 2026
Last updated 24 July 2024
Last updated 24 July 2024
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via putqpelfallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Libde265 v1.0.8 was discovered to contain a segmentation violation via applysaointernal<unsigned short> in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via putepelhvfallback<unsigned short> in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Last updated 24 July 2024
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via putqpel00fallback16 in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024