CVE-2024-38949
published 2024-06-26CVE-2024-38949: Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.44%
35.4th percentile
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libde265 | — | — |
| struktur | libde265 | — | — |
| ubuntu | libde265 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libde265 vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 3.3
CVE-2026-45382 [LOW] libde265 vulnerabilities
Title: libde265 vulnerabilities
Summary: Several security issues were fixed in libde265.
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resultin
Debian
CVE-2024-38949: libde265 - Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash...
vendor_debian·2024·CVSS 6.5
CVE-2024-38949 [MEDIUM] CVE-2024-38949: libde265 - Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash...
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-w54f-vq4c-7637: Heap Buffer Overflow vulnerability in Libde265 v1
ghsa_unreviewed·2024-06-26
CVE-2024-38949 [MEDIUM] CWE-122 GHSA-w54f-vq4c-7637: Heap Buffer Overflow vulnerability in Libde265 v1
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
OSV
CVE-2024-38949: Heap Buffer Overflow vulnerability in Libde265 v1
osv·2024-06-26·CVSS 6.5
CVE-2024-38949 [MEDIUM] CVE-2024-38949: Heap Buffer Overflow vulnerability in Libde265 v1
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-26
Published