Struktur Libde265 vulnerabilities
62 known vulnerabilities affecting struktur/libde265.
Total CVEs
62
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM46LOW1
Vulnerabilities
Page 1 of 4
CVE-2022-1253P3CRITICALCVSS 9.8≤ 1.0.82022-04-06
CVE-2022-1253 [CRITICAL] CWE-122 CVE-2022-1253: Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. Th
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
nvdosv
CVE-2023-49465P3HIGHCVSS 8.8v1.0.142023-12-07
CVE-2023-49465 [HIGH] CWE-787 CVE-2023-49465: Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatia
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.
nvdosv
CVE-2023-49467P3HIGHCVSS 8.8v1.0.142023-12-07
CVE-2023-49467 [HIGH] CWE-787 CVE-2023-49467: Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combin
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc.
nvdosv
CVE-2020-21598P3HIGHCVSS 8.8v1.0.42021-09-16
CVE-2020-21598 [HIGH] CWE-787 CVE-2020-21598: libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, w
libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.
nvdosv
CVE-2023-49468P3HIGHCVSS 8.8v1.0.142023-12-07
CVE-2023-49468 [HIGH] CWE-787 CVE-2023-49468: Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding
Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.
nvdosv
CVE-2023-27103P3HIGHCVSS 8.8v1.0.112023-03-15
CVE-2023-27103 [HIGH] CWE-787 CVE-2023-27103: Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated
Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc.
nvdosv
CVE-2023-43887P3HIGHCVSS 8.1v1.0.122023-11-22
CVE-2023-43887 [HIGH] CWE-120 CVE-2023-43887: Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and nu
Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.
nvdosv
CVE-2026-33164P3HIGHCVSS 7.5fixed in 1.0.172026-03-20
CVE-2026-33164 [HIGH] CWE-122 CVE-2026-33164: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malfo
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
nvdosv
CVE-2026-49295P3HIGHCVSS 7.1fixed in 1.0.202026-06-19
CVE-2026-49295 [HIGH] CWE-787 CVE-2026-49295: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a craft
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individ
nvd
CVE-2022-47665P4HIGHCVSS 7.8v1.0.92023-03-03
CVE-2022-47665 [HIGH] CWE-787 CVE-2022-47665: Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, in
Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)
nvdosv
CVE-2026-49346P3HIGHCVSS 7.1fixed in 1.1.02026-06-19
CVE-2026-49346 [HIGH] CWE-190 CVE-2026-49346: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafte
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_im
nvd
CVE-2022-47664P4HIGHCVSS 7.8v1.0.92023-03-03
CVE-2022-47664 [HIGH] CWE-120 CVE-2022-47664: Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
nvdosv
CVE-2022-47655P4HIGHCVSS 7.8v1.0.92023-01-05
CVE-2022-47655 [HIGH] CWE-787 CVE-2022-47655: Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback
nvdosv
CVE-2023-25221P4HIGHCVSS 7.8v1.0.102023-03-01
CVE-2023-25221 [HIGH] CWE-787 CVE-2023-25221: Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatia
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.
nvdosv
CVE-2021-35452P4MEDIUMCVSS 6.5v1.0.82022-01-10
CVE-2021-35452 [MEDIUM] CWE-125 CVE-2021-35452: An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
nvdosv
CVE-2020-21597P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21597 [MEDIUM] CWE-787 CVE-2020-21597: libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited vi
libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.
nvdosv
CVE-2020-21596P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21596 [MEDIUM] CWE-120 CVE-2020-21596: libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exp
libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.
nvdosv
CVE-2020-21600P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21600 [MEDIUM] CWE-787 CVE-2020-21600: libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, w
libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.
nvdosv
CVE-2020-21599P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21599 [MEDIUM] CWE-787 CVE-2020-21599: libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which
libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.
nvdosv
CVE-2020-21602P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21602 [MEDIUM] CWE-787 CVE-2020-21602: libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, whi
libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.
nvdosv
1 / 4Next →