cbcvebase.

Debian Libde265 vulnerabilities

58 known vulnerabilities affecting debian/libde265.

Total CVEs
58
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM43LOW2

Vulnerabilities

Page 3 of 3
CVE-2020-21605P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1 (bookworm)2020
CVE-2020-21605 [MEDIUM] CVE-2020-21605: libde265 - libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function... libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file. Scope: local bookworm: resolved (fixed in 1.0.9-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1) sid: resolved (fixed in 1.0.9-1) trixie: resolved (fixed in 1.0.9-1)
debian
CVE-2022-43245P4MEDIUMCVSS 6.5fixed in libde265 1.0.11-1 (bookworm)2022
CVE-2022-43245 [MEDIUM] CVE-2022-43245: libde265 - Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao... Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in 1.0.11-1
debian
CVE-2025-29482P4MEDIUMCVSS 6.2fixed in libde265 1.0.7-1 (bookworm)2025
CVE-2025-29482 [MEDIUM] CVE-2025-29482: libde265 - Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execu... Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265. Scope: local bookworm: resolved (fixed in 1.0.7-1) bullseye: resolved (fixed in 1.0.7-1) forky: resolved (fixed in 1.0.7-1) sid: resolved (fixed in 1.0.7-1) trixie: resolved (fixed in 1.0.7-1)
debian
CVE-2022-43238P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1.1 (bookworm)2022
CVE-2022-43238 [MEDIUM] CVE-2022-43238: libde265 - Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_... Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file. Scope: local bookworm: resolved (fixed in 1.0.9-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1.1) sid: resolved (f
debian
CVE-2022-43241P4MEDIUMCVSS 6.5fixed in libde265 1.0.9-1.1 (bookworm)2022
CVE-2022-43241 [MEDIUM] CVE-2022-43241: libde265 - Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_... Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file. Scope: local bookworm: resolved (fixed in 1.0.9-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.9-1.1) sid: resolved (fix
debian
CVE-2023-24751P4MEDIUMCVSS 6.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24751 [MEDIUM] CVE-2023-24751: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.11-1) sid: resolved (fixed in
debian
CVE-2025-61147P4LOWCVSS 6.2fixed in libde265 1.0.18-1 (forky)2025
CVE-2025-61147 [MEDIUM] CVE-2025-61147: libde265 - strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault... strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.0.18-1) sid: resolved (fixed in 1.0.18-1) trixie: open
debian
CVE-2021-36410P4MEDIUMCVSS 5.5fixed in libde265 1.0.8-1.1 (bookworm)2021
CVE-2021-36410 [MEDIUM] CVE-2021-36410: libde265 - A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in func... A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.8-1.1) sid: resolved (fixed in 1.0.8-1.1) trixie: resolved (fixed in 1.0.8-1.1)
debian
CVE-2026-33165P4MEDIUMCVSS 5.5fixed in libde265 1.0.18-1 (forky)2026
CVE-2026-33165 [MEDIUM] CVE-2026-33165: libde265 - libde265 is an open source implementation of the h.265 video codec. Prior to ver... libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to i
debian
CVE-2021-36408P4MEDIUMCVSS 5.5fixed in libde265 1.0.8-1.1 (bookworm)2021
CVE-2021-36408 [MEDIUM] CVE-2021-36408: libde265 - An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in int... An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.8-1.1) sid: resolved (fixed in 1.0.8-1.1) trixie: resolved (fixed in 1.0.8-1.1)
debian
CVE-2021-36411P4MEDIUMCVSS 5.5fixed in libde265 1.0.8-1.1 (bookworm)2021
CVE-2021-36411 [MEDIUM] CVE-2021-36411: libde265 - An issue has been found in libde265 v1.0.8 due to incorrect access control. A SE... An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service. Scope: local bookworm: resolved (fixed in 1.0.8-1.1) bullseye: resolved (fixe
debian
CVE-2023-24756P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24756 [MEDIUM] CVE-2023-24756: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.1
debian
CVE-2023-24754P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24754 [MEDIUM] CVE-2023-24754: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0
debian
CVE-2023-24757P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24757 [MEDIUM] CVE-2023-24757: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.
debian
CVE-2023-24752P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24752 [MEDIUM] CVE-2023-24752: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.
debian
CVE-2023-24758P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24758 [MEDIUM] CVE-2023-24758: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0
debian
CVE-2023-24755P4MEDIUMCVSS 5.5fixed in libde265 1.0.11-1 (bookworm)2023
CVE-2023-24755 [MEDIUM] CVE-2023-24755: libde265 - libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put... libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. Scope: local bookworm: resolved (fixed in 1.0.11-1) bullseye: resolved (fixed in 1.0.11-0+deb11u1) forky: resolved (fixed in 1.0.1
debian
CVE-2023-51792P4LOWCVSS 3.3fixed in libde265 1.0.13-1 (forky)2023
CVE-2023-51792 [LOW] CVE-2023-51792: libde265 - Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cau... Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.0.13-1) sid: resolved (fixed in 1.0.13-1) trixie: resolved (fixed in 1.0.13-1)
debian
Debian Libde265 vulnerabilities | cvebase