Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.2) | 0.24% | — | Struktur Libheif | 7/4/2025 | 17/6/2026 | Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265. | |
| Analizada | Alta (8.1) | 0.77% | — | Struktur LibheifDebian Linux | 15/10/2024 | 17/6/2026 | In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. | |
| Analizada | Media (6.5) | 0.45% | — | Struktur Libde265 | 26/6/2024 | 17/6/2026 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. | |
| Analizada | Media (6.5) | 0.40% | — | Struktur Libde265 | 26/6/2024 | 17/6/2026 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc | |
| Aplazada | Baja (3.3) | 0.23% | — | Struktur Libde265AI | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000. | |
| Analizada | Alta (7.5) | 0.69% | — | Struktur Libheif | 5/3/2024 | 17/6/2026 | libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack. | |
| Modificada | Alta (8.8) | 0.87% | — | Struktur Libde265 | 7/12/2023 | 17/6/2026 | Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. | |
| Modificada | Alta (8.8) | 0.77% | — | Struktur Libde265 | 7/12/2023 | 17/6/2026 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc. | |
| Modificada | Alta (8.8) | 0.80% | — | Struktur Libde265 | 7/12/2023 | 17/6/2026 | Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. | |
| Modificada | Alta (8.8) | 0.76% | — | Struktur Libheif | 7/12/2023 | 17/6/2026 | libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci. | |
| Modificada | Alta (8.8) | 0.77% | — | Struktur Libheif | 7/12/2023 | 17/6/2026 | libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc. | |
| Modificada | Alta (8.8) | 0.80% | — | Struktur Libheif | 7/12/2023 | 17/6/2026 | libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc. | |
| Modificada | Alta (8.8) | 0.76% | — | Struktur Libheif | 7/12/2023 | 17/6/2026 | libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image. | |
| Modificada | Alta (8.1) | 0.98% | — | Struktur Libde265 | 22/11/2023 | 17/6/2026 | Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump. | |
| Modificada | Media (6.5) | 0.77% | — | Struktur Libde265 | 16/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component. | |
| Modificada | Media (6.5) | 0.93% | — | Struktur LibheifFedoraproject Fedora | 5/5/2023 | 17/6/2026 | A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service. | |
| Modificada | Alta (8.8) | 0.85% | — | Struktur Libde265 | 15/3/2023 | 17/6/2026 | Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc. | |
| Modificada | Media (6.5) | 0.67% | — | Struktur Libde265 | 15/3/2023 | 17/6/2026 | Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc. | |
| Modificada | Alta (7.8) | 0.33% | — | Struktur Libde265 | 3/3/2023 | 17/6/2026 | Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int) | |
| Modificada | Alta (7.8) | 0.31% | — | Struktur Libde265 | 3/3/2023 | 17/6/2026 | Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse | |
| Modificada | Alta (7.8) | 0.33% | — | Struktur Libde265Debian Linux | 1/3/2023 | 17/6/2026 | Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc. | |
| Modificada | Media (5.5) | 0.29% | — | Struktur Libde265Debian Linux | 1/3/2023 | 17/6/2026 | libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. | |
| Modificada | Media (5.5) | 0.29% | — | Struktur Libde265Debian Linux | 1/3/2023 | 17/6/2026 | libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. | |
| Modificada | Media (5.5) | 0.29% | — | Struktur Libde265Debian Linux | 1/3/2023 | 17/6/2026 | libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. | |
| Modificada | Media (5.5) | 0.29% | — | Struktur Libde265Debian Linux | 1/3/2023 | 17/6/2026 | libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file. |