vciy

CVEs we hold for Strukturag

Records whose assigning authority named Strukturag as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-84451libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds readstrukturag libheif
CVE-2026-84450libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289)strukturag libheif
CVE-2026-84449libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGVstrukturag libheif
CVE-2026-84448libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data /…strukturag libheif
CVE-2026-84447libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits…strukturag libheif
CVE-2026-84446libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing…strukturag libheif
CVE-2026-84444libheif uncompressed tiled image encoding allows out-of-bounds writestrukturag libheif
CVE-2026-84384libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoSstrukturag libheif
CVE-2026-84383libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` itemsstrukturag libheif
CVE-2026-62377libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file…strukturag libheif
CVE-2026-62292libheif: Out-of-bounds read in uncompressed unci tile range slicingstrukturag libheif
CVE-2026-62291libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha…strukturag libheif
CVE-2026-62289libheif: Integer underflow in Fraction constructor via double clap transform applicationstrukturag libheif
CVE-2026-54241libde265: SAO sequential filter heap buffer overflow via signed integer overflowstrukturag libde265
CVE-2026-54240libde265: Pixel accessor signed integer overflow causes heap OOB read/writestrukturag libde265
CVE-2026-50142libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)strukturag libheif
CVE-2026-49346libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflowstrukturag libde265
CVE-2026-49337libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`strukturag libde265
CVE-2026-49295libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPSstrukturag libde265
CVE-2026-49271libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoderstrukturag libheif
CVE-2026-48029libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflowstrukturag libheif
CVE-2026-47714libheif has integer overflow in inline mask size calculation that causes undersized buffer allocationstrukturag libheif
CVE-2026-47709libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispestrukturag libheif
CVE-2026-47254libheif Has Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Accessstrukturag libheif
CVE-2026-47251libheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2strukturag libheif
CVE-2026-47247libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocationstrukturag libheif
CVE-2026-47178libheif has Heap Out Of Bounds Write in unci subsystemstrukturag libheif
CVE-2026-45383libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access —…strukturag libde265
CVE-2026-45382libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometrystrukturag libde265
CVE-2026-41071libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample countstrukturag libheif
CVE-2026-41069libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)strukturag libheif
CVE-2026-3950strukturag libheif stsz/stts track.cc load out-of-boundsstrukturag libheif
CVE-2026-3949strukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-boundsstrukturag libheif
CVE-2026-33165heap out-of-bounds write in libde265 1.0.16strukturag libde265
CVE-2026-33164NULL Pointer Dereference in libde265strukturag libde265
CVE-2026-32882libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stridestrukturag libheif
CVE-2026-32814libheif: Uninitialized Heap Memory Information Leak via Failed Grid Tilesstrukturag libheif
CVE-2026-32741libheif has a heap buffer overflow in decode_mask_image()strukturag libheif
CVE-2026-32740libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositingstrukturag libheif
CVE-2026-32739libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookupstrukturag libheif
CVE-2026-32738libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunkstrukturag libheif
CVE-2025-68431libheif has Potential Heap Buffer Over-Readstrukturag libheif
CVE-2022-1253Heap-based Buffer Overflow in strukturag/libde265strukturag/libde265

43 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.