Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.2)0.24%—Struktur Libheif7/4/202517/6/2026
Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.
AnalizadaAlta (8.1)0.77%—Struktur LibheifDebian Linux15/10/202417/6/2026
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
AnalizadaMedia (6.5)0.45%—Struktur Libde26526/6/202417/6/2026
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.
AnalizadaMedia (6.5)0.40%—Struktur Libde26526/6/202417/6/2026
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
AplazadaBaja (3.3)0.23%—Struktur Libde265AI19/4/202417/6/2026
Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.
AnalizadaAlta (7.5)0.69%—Struktur Libheif5/3/202417/6/2026
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
ModificadaAlta (8.8)0.87%—Struktur Libde2657/12/202317/6/2026
Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.
ModificadaAlta (8.8)0.77%—Struktur Libde2657/12/202317/6/2026
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc.
ModificadaAlta (8.8)0.80%—Struktur Libde2657/12/202317/6/2026
Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.
ModificadaAlta (8.8)0.76%—Struktur Libheif7/12/202317/6/2026
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci.
ModificadaAlta (8.8)0.77%—Struktur Libheif7/12/202317/6/2026
libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
ModificadaAlta (8.8)0.80%—Struktur Libheif7/12/202317/6/2026
libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
ModificadaAlta (8.8)0.76%—Struktur Libheif7/12/202317/6/2026
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image.
ModificadaAlta (8.1)0.98%—Struktur Libde26522/11/202317/6/2026
Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.
ModificadaMedia (6.5)0.77%—Struktur Libde26516/11/202317/6/2026
Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component.
ModificadaMedia (6.5)0.93%—Struktur LibheifFedoraproject Fedora5/5/202317/6/2026
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
ModificadaAlta (8.8)0.85%—Struktur Libde26515/3/202317/6/2026
Libde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc.
ModificadaMedia (6.5)0.67%—Struktur Libde26515/3/202317/6/2026
Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc.
ModificadaAlta (7.8)0.33%—Struktur Libde2653/3/202317/6/2026
Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)
ModificadaAlta (7.8)0.31%—Struktur Libde2653/3/202317/6/2026
Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
ModificadaAlta (7.8)0.33%—Struktur Libde265Debian Linux1/3/202317/6/2026
Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
ModificadaMedia (5.5)0.29%—Struktur Libde265Debian Linux1/3/202317/6/2026
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Orbitaley — Vulnerabilidades