cbcvebase.

Debian Libde265 vulnerabilities

58 known vulnerabilities affecting debian/libde265.

Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM43LOW2

Vulnerabilities

Page 1 of 3
CVE-2022-1253P3CRITICALCVSS 9.8fixed in libde265 1.0.8-1.1 (bookworm)2022
CVE-2022-1253 [CRITICAL] CVE-2022-1253: libde265 - Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and... Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.8-1.1) sid: res
debian
CVE-2023-49465P3HIGHCVSS 8.8fixed in libde265 1.0.11-1+deb12u2 (bookworm)2023
CVE-2023-49465 [HIGH] CVE-2023-49465: libde265 - Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability ... Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. Scope: local bookworm: resolved (fixed in 1.0.11-1+deb12u2) bullseye: resolved (fixed in 1.0.11-0+deb11u3) forky: resolved (fixed in 1.0.15-1) sid: resolved (fixed in 1.0.15-1) trixie: resolved (fixed in 1.0.15-1)
debian
CVE-2023-49467P3HIGHCVSS 8.8fixed in libde265 1.0.11-1+deb12u2 (bookworm)2023
CVE-2023-49467 [HIGH] CVE-2023-49467: libde265 - Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability ... Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc. Scope: local bookworm: resolved (fixed in 1.0.11-1+deb12u2) bullseye: resolved (fixed in 1.0.11-0+deb11u3) forky: resolved (fixed in 1.0.15-1) sid: resolved (fixed in 1.0.15-1) trixie: resolved (fixed in 1.0.1
debian
CVE-2020-21598P3HIGHCVSS 8.8fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21598 [HIGH] CVE-2020-21598: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pr... libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2023-49468P3HIGHCVSS 8.8fixed in libde265 1.0.11-1+deb12u2 (bookworm)2023
CVE-2023-49468 [HIGH] CVE-2023-49468: libde265 - Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerabilit... Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. Scope: local bookworm: resolved (fixed in 1.0.11-1+deb12u2) bullseye: resolved (fixed in 1.0.11-0+deb11u3) forky: resolved (fixed in 1.0.15-1) sid: resolved (fixed in 1.0.15-1) trixie: resolved (fixed in 1.0.15-1)
debian
CVE-2023-27103P3HIGHCVSS 8.8fixed in libde265 1.0.11-1+deb12u1 (bookworm)2023
CVE-2023-27103 [HIGH] CVE-2023-27103: libde265 - Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the functi... Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. Scope: local bookworm: resolved (fixed in 1.0.11-1+deb12u1) bullseye: resolved (fixed in 1.0.11-0+deb11u2) forky: resolved (fixed in 1.0.12-1) sid: resolved (fixed in 1.0.12-1) trixie: resolved (fixed in 1.0.12-1)
debian
CVE-2026-33164P3HIGHCVSS 8.7fixed in libde265 1.0.18-1 (forky)2026
CVE-2026-33164 [HIGH] CVE-2026-33164: libde265 - libde265 is an open source implementation of the h.265 video codec. Prior to ver... libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.0.18-1) sid: resolved (fixed in 1.0.18-1) trixie: ope
debian
CVE-2023-43887P3HIGHCVSS 8.1fixed in libde265 1.0.11-1+deb12u1 (bookworm)2023
CVE-2023-43887 [HIGH] CVE-2023-43887: libde265 - Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num... Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump. Scope: local bookworm: resolved (fixed in 1.0.11-1+deb12u1) bullseye: resolved (fixed in 1.0.11-0+deb11u2) forky: resolved (fixed in 1.0.13-1) sid: resolved (fixed in 1.0.13-1) trixie: resolved (fixed in
debian
CVE-2022-47665P4HIGHCVSS 7.8fixed in libde265 1.0.11-1 (bookworm)2022
CVE-2022-47665 [HIGH] CVE-2022-47665: libde265 - Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_Slic... Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int) Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in 1.0.11-1) trixie: resolved (fixed in 1.0.11-1)
debian
CVE-2022-47664P4HIGHCVSS 7.8fixed in libde265 1.0.11-1 (bookworm)2022
CVE-2022-47664 [HIGH] CVE-2022-47664: libde265 - Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_... Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in 1.0.11-1) trixie: resolved (fixed in 1.0.11-1)
debian
CVE-2022-47655P4HIGHCVSS 7.8fixed in libde265 1.0.9-1.1 (bookworm)2022
CVE-2022-47655 [HIGH] CVE-2022-47655: libde265 - Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallba... Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback Scope: local bookworm: resolved (fixed in 1.0.9-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1.1) sid: resolved (fixed in 1.0.9-1.1) trixie: resolved (fixed in 1.0.9-1.1)
debian
CVE-2023-25221P4HIGHCVSS 7.8fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-25221 [HIGH] CVE-2023-25221: libde265 - Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability ... Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in 1.0.11-1) trixie: resolved (fixed in 1.0.11-1)
debian
CVE-2021-35452P4MEDIUMCVSS 6.5fixed in libde265 1.0.8-1.1 (bookworm)2021
CVE-2021-35452 [MEDIUM] CVE-2021-35452: libde265 - An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEG... An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.8-1.1) sid: resolved (fixed in 1.0.8-1.1) trixie: resolved (fixed in 1.0.8-1.1)
debian
CVE-2020-21597P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21597 [MEDIUM] CVE-2020-21597: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which... libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2020-21596P4MEDIUMCVSS 6.5fixed in libde265 1.0.11-1 (bookworm)2020
CVE-2020-21596 [MEDIUM] CVE-2020-21596: libde265 - libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit functi... libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in 1.0.11-1) trixie: resolved (fixed in 1.0.11-1)
debian
CVE-2020-21600P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21600 [MEDIUM] CVE-2020-21600: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_... libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2020-21599P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21599 [MEDIUM] CVE-2020-21599: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zs... libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2020-21602P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21602 [MEDIUM] CVE-2020-21602: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fa... libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2021-36409P4HIGHCVSS 7.8fixed in libde265 1.0.8-1.1 (bookworm)2021
CVE-2021-36409 [HIGH] CVE-2021-36409: libde265 - There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:92... There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1
debian
CVE-2020-21594P4MEDIUMCVSS 6.5fixed in libde265 1.0.3-1 (bookworm)2020
CVE-2020-21594 [MEDIUM] CVE-2020-21594: libde265 - libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback func... libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.3-1) sid: resolved (fixed in 1.0.3-1) trixie: resolved (fixed in 1.0.3-1)
debian
Debian Libde265 vulnerabilities | cvebase