Known vulnerabilities in libheif (Debian package)
Vendor:
Debian
Software:
libheif (Debian package)
Software CPE:
cpe:2.3:o:debian:libheif_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
22
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (22)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146739 - Out-of-bounds read CVE-2026-84451 |
CWE-125 | Medium | 1.23.4-1~deb13u1 | 02.09.2026 |
SB2026090248 SB20260928239 SB2026093054 |
||
| #VU146729 - Reachable Assertion CVE-2026-84450 |
CWE-617 | Low | 1.23.4-1~deb13u1 | 02.09.2026 |
SB2026090248 SB20260928239 SB2026093054 |
||
| #VU145256 - Out-of-bounds read CVE-2026-84448 |
CWE-125 | Low | 1.23.4-1~deb13u1 | 25.08.2026 |
SB2026082574 SB20260928239 SB2026092969 and 1 more |
||
| #VU145254 - Out-of-bounds write CVE-2026-84444 |
CWE-787 | Medium | 1.23.4-1~deb13u1 | 25.08.2026 |
SB2026082574 SB20260928239 SB2026093054 |
||
| #VU145246 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2026-84384 |
CWE-409 | Medium | 1.23.4-1~deb13u1 | 25.08.2026 |
SB2026082574 SB20260928239 SB2026092969 and 1 more |
||
| #VU145243 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2026-84446 |
CWE-835 | Medium | 1.23.4-1~deb13u1 | 25.08.2026 |
SB2026082574 SB20260928239 SB2026092969 and 1 more |
||
| #VU145239 - Allocation of Resources Without Limits or Throttling CVE-2026-84447 |
CWE-770 | Medium | 1.23.4-1~deb13u1 | 25.08.2026 |
SB2026082574 SB20260928239 SB2026092969 and 1 more |
||
| #VU135516 - Out-of-bounds read CVE-2026-62292 |
CWE-125 | Medium | 1.19.8-1+deb13u1 | 26.06.2026 |
SB2026062684 SB2026081953 SB2026081955 and 3 more |
||
| #VU135515 - Integer underflow CVE-2026-62289 |
CWE-191 | Low | 1.19.8-1+deb13u1 | 26.06.2026 |
SB2026062684 SB2026081953 SB2026081955 and 5 more |
||
| #VU135510 - Out-of-bounds read CVE-2026-49271 |
CWE-125 | Medium | 1.19.8-1+deb13u1 | 26.06.2026 |
SB2026062682 SB2026070131 SB2026081953 and 2 more |
||
| #VU131986 - Out-of-bounds read CVE-2026-48029 |
CWE-125 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026072474 SB2026081953 and 2 more |
||
| #VU131978 - Heap-based Buffer Overflow CVE-2026-32741 |
CWE-122 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026081953 |
||
| #VU131977 - Out-of-bounds write CVE-2026-32740 |
CWE-787 | High | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026081953 |
||
| #VU131973 - Out-of-bounds read CVE-2026-32882 |
CWE-125 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026072954 SB2026081953 |
||
| #VU131972 - Integer overflow CVE-2026-47714 |
CWE-190 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB20260715102 SB2026072474 and 3 more |
||
| #VU131961 - Out-of-bounds write CVE-2026-47178 |
CWE-787 | High | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026070131 SB2026081953 and 2 more |
||
| #VU131959 - Use of Uninitialized Resource CVE-2026-47247 |
CWE-908 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB2026081953 SB2026092303 and 1 more |
||
| #VU131958 - NULL Pointer Dereference CVE-2026-47709 |
CWE-476 | Medium | 1.19.8-1+deb13u1 | 20.05.2026 |
SB2026052069 SB20260715102 SB2026072474 and 3 more |
||
| #VU121163 - Out-of-bounds read CVE-2025-68431 |
CWE-125 | Medium | 1.19.8-1+deb13u1 | 12.01.2026 |
SB2026011231 SB2026011243 SB2026011253 and 6 more |
||
| #VU76229 - Divide By Zero CVE-2023-29659 |
CWE-369 | Medium | 1.15.1-1+deb12u1 | 16.05.2023 |
SB20230516120 SB2023051701 SB2023071823 and 4 more |
Showing elements 1 - 20 out of 22