Vulnerabilidades en strukturag

43 resultados
Análisis Vexday

A Struktur AG registra 27 vulnerabilidades na base, com 21 publicadas nos últimos 90 dias, indicando ritmo intenso de descobertas recentes. Nenhuma dessas falhas está sob ataque ativo confirmado (KEV) e não há críticas CVSS, o que reduz a urgência operacional imediata. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementações em linguagens de baixo nível, sugerindo risco moderado de execução remota dependente de contexto.

CVE-2022-1253HIGHHeap-based Buffer Overflow in strukturag/libde265EPSS 2.1%CVE-2026-32740HIGHlibheif: Heap-Buffer-Overflow Write in Grid Tile Chroma CompositingEPSS 0.8%CVE-2026-32882HIGHlibheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha strideEPSS 0.7%CVE-2026-50142HIGHlibheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)EPSS 0.7%CVE-2026-84383CRITICALlibheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` itemsEPSS 0.6%CVE-2026-62292HIGHlibheif: Out-of-bounds read in uncompressed unci tile range slicingEPSS 0.5%CVE-2026-84447HIGHlibheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoSEPSS 0.5%CVE-2026-84384HIGHlibheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoSEPSS 0.5%CVE-2026-33164HIGHNULL Pointer Dereference in libde265EPSS 0.5%CVE-2026-47247HIGHlibheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane AllocationEPSS 0.5%CVE-2026-84444HIGHlibheif uncompressed tiled image encoding allows out-of-bounds writeEPSS 0.5%CVE-2026-84446HIGHlibheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_framesEPSS 0.5%CVE-2026-32741HIGHlibheif has a heap buffer overflow in decode_mask_image()EPSS 0.4%CVE-2026-41071MEDIUMlibheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample countEPSS 0.4%CVE-2026-84449LOWlibheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGVEPSS 0.4%CVE-2026-45382MEDIUMlibde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometryEPSS 0.4%CVE-2025-68431MEDIUMlibheif has Potential Heap Buffer Over-ReadEPSS 0.4%CVE-2026-45383MEDIUMlibde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18EPSS 0.4%CVE-2026-62377MEDIUMlibheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)EPSS 0.4%CVE-2026-62289MEDIUMlibheif: Integer underflow in Fraction constructor via double clap transform applicationEPSS 0.4%