Struktur Libde265 vulnerabilities
62 known vulnerabilities affecting struktur/libde265.
Total CVEs
62
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM46LOW1
Vulnerabilities
Page 3 of 4
CVE-2022-43252P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43252 [MEDIUM] CWE-787 CVE-2022-43252: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallb
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2022-43253P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43253 [MEDIUM] CWE-787 CVE-2022-43253: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pr
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2022-43249P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43249 [MEDIUM] CWE-787 CVE-2022-43249: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallb
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback in fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2022-43235P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43235 [MEDIUM] CWE-787 CVE-2022-43235: Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2020-21605P4MEDIUMCVSS 6.5v1.0.42021-09-16
CVE-2020-21605 [MEDIUM] CVE-2020-21605: libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be explo
libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.
nvdosv
CVE-2022-43245P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43245 [MEDIUM] CWE-787 CVE-2022-43245: Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned s
Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2025-29482P4MEDIUMCVSS 6.2≥ 0, < 1.0.7-12025-04-07
CVE-2025-29482 [MEDIUM] CVE-2025-29482: Buffer Overflow vulnerability in libheif 1
Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.
osv
CVE-2022-43238P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43238 [MEDIUM] CWE-400 CVE-2022-43238: Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2022-43241P4MEDIUMCVSS 6.5v1.0.82022-11-02
CVE-2022-43241 [MEDIUM] CWE-787 CVE-2022-43241: Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in ss
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
nvdosv
CVE-2023-24751P4MEDIUMCVSS 6.5v1.0.102023-03-01
CVE-2023-24751 [MEDIUM] CWE-476 CVE-2023-24751: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at m
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv
CVE-2025-61147P4MEDIUMCVSS 6.2fixed in 1.0.172026-02-23
CVE-2025-61147 [MEDIUM] CWE-120 CVE-2025-61147: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component d
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
nvdosv
CVE-2021-36410P4MEDIUMCVSS 5.5v1.0.82022-01-10
CVE-2021-36410 [MEDIUM] CWE-787 CVE-2021-36410: A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fal
A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.
nvdosv
CVE-2026-33165P4MEDIUMCVSS 5.0fixed in 1.0.172026-03-20
CVE-2026-33165 [MEDIUM] CWE-787 CVE-2026-33165: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a craft
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHe
nvdosv
CVE-2021-36408P4MEDIUMCVSS 5.5v1.0.82022-01-10
CVE-2021-36408 [MEDIUM] CWE-416 CVE-2021-36408: An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decodi
An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.
nvdosv
CVE-2021-36411P4MEDIUMCVSS 5.5v1.0.82022-01-10
CVE-2021-36411 [MEDIUM] CWE-125 CVE-2021-36411: An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ
An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.
nvdosv
CVE-2023-24755P4MEDIUMCVSS 5.5v1.0.102023-03-01
CVE-2023-24755 [MEDIUM] CWE-476 CVE-2023-24755: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fal
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv
CVE-2023-24757P4MEDIUMCVSS 5.5v1.0.102023-03-01
CVE-2023-24757 [MEDIUM] CWE-476 CVE-2023-24757: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv
CVE-2023-24754P4MEDIUMCVSS 5.5v1.0.102023-03-01
CVE-2023-24754 [MEDIUM] CWE-476 CVE-2023-24754: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pr
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv
CVE-2023-24752P4MEDIUMCVSS 5.5v1.0.102023-03-01
CVE-2023-24752 [MEDIUM] CWE-476 CVE-2023-24752: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_p
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv
CVE-2023-24756P4MEDIUMCVSS 5.5v1.0.102023-03-01
CVE-2023-24756 [MEDIUM] CWE-476 CVE-2023-24756: libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
nvdosv