CVE-2026-33164
- EPSS 0.05%
- Veröffentlicht 20.03.2026 20:33:04
- Zuletzt bearbeitet 23.03.2026 20:05:09
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
- EPSS 0.01%
- Veröffentlicht 20.03.2026 20:32:36
- Zuletzt bearbeitet 23.03.2026 20:09:04
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change w...
CVE-2025-61147
- EPSS 0.01%
- Veröffentlicht 23.02.2026 00:00:00
- Zuletzt bearbeitet 24.03.2026 12:25:34
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
CVE-2024-38950
- EPSS 0.18%
- Veröffentlicht 26.06.2024 20:15:16
- Zuletzt bearbeitet 06.06.2025 17:15:28
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.
CVE-2024-38949
- EPSS 0.13%
- Veröffentlicht 26.06.2024 20:15:16
- Zuletzt bearbeitet 06.06.2025 17:15:02
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
CVE-2023-49468
- EPSS 0.22%
- Veröffentlicht 07.12.2023 20:15:38
- Zuletzt bearbeitet 21.11.2024 08:33:26
Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.
CVE-2023-49467
- EPSS 0.18%
- Veröffentlicht 07.12.2023 20:15:38
- Zuletzt bearbeitet 21.11.2024 08:33:26
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc.
CVE-2023-49465
- EPSS 0.14%
- Veröffentlicht 07.12.2023 20:15:38
- Zuletzt bearbeitet 21.11.2024 08:33:26
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.
CVE-2023-43887
- EPSS 0.17%
- Veröffentlicht 22.11.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:57
Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.
CVE-2023-47471
- EPSS 0.3%
- Veröffentlicht 16.11.2023 04:15:06
- Zuletzt bearbeitet 21.11.2024 08:30:20
Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component.