Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-3950

5 месяцев назад

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2026-3950

5 месяцев назад

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-3950

5 месяцев назад

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-3950

5 месяцев назад

A vulnerability was identified in strukturag libheif up to 1.21.2. Thi ...

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-cp66-x46c-28rg

5 месяцев назад

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2026-05076

6 месяцев назад

Уязвимость функции Track::load() компонента stsz/stts декодера и кодировщика форматов файлов libheif, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20974-1

около 2 месяцев назад

Security update for libheif

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2622-1

около 2 месяцев назад

Security update for libheif

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-3950

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-3950

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-3950

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-3950

A vulnerability was identified in strukturag libheif up to 1.21.2. Thi ...

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-cp66-x46c-28rg

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05076

Уязвимость функции Track::load() компонента stsz/stts декодера и кодировщика форматов файлов libheif, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20974-1

Security update for libheif

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2622-1

Security update for libheif

около 2 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.