Search CVE reports


Toggle filters

11 – 15 of 15 results


CVE-2023-0996

Medium priority

Some fixes available 2 of 3

There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call.

1 affected package

libheif

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libheif Not affected Fixed Fixed Not affected Ignored
Show less packages

CVE-2020-23109

Medium priority

Some fixes available 1 of 6

Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.

1 affected package

libheif

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libheif Not affected Not affected Fixed Ignored Ignored
Show less packages

CVE-2020-19499

Medium priority
Not affected

An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.

1 affected package

libheif

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libheif Not affected Not affected Not affected Ignored
Show less packages

CVE-2020-19498

Medium priority
Not affected

Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.

1 affected package

libheif

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libheif Not affected Not affected Not affected Ignored
Show less packages

CVE-2019-11471

Medium priority

Some fixes available 11 of 13

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

1 affected package

libheif

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libheif Fixed Fixed Fixed Fixed Not in release
Show less packages