📦 Libheif

by Struktur

🔍 What is Libheif?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-41311

HIGH CVSS 8.1 Oct 15, 2024

CVE-2024-41311 is an out-of-bounds read/write vulnerability in Libheif's ImageOverlay::parse() function when processing malicious HEIF files with forged offsets. This allows attackers to potentially e...

CVE-2024-25269

HIGH CVSS 7.5 Mar 5, 2024

A memory leak vulnerability in libheif's JpegEncoder::Encode function allows attackers to cause denial of service by exhausting system memory. This affects all applications using vulnerable versions o...

CVE-2023-0996

HIGH CVSS 7.8 Feb 24, 2023

This vulnerability allows attackers to exploit a buffer overflow in the strided image data parsing code of the emscripten wrapper for libheif by providing a crafted image file. This could lead to arbi...

CVE-2020-23109

HIGH CVSS 8.1 Nov 3, 2021

A buffer overflow vulnerability in libheif's color conversion function allows attackers to cause denial of service or information disclosure by processing a malicious HEIF image file. This affects any...

CVE-2020-19499

HIGH CVSS 8.8 Jul 21, 2021

This vulnerability in libheif's Box_iref::get_references function allows attackers to trigger an invalid memory read, potentially causing denial of service or arbitrary code execution. It affects appl...

CVE-2025-68431

MEDIUM CVSS 6.5 Dec 29, 2025

CVE-2025-68431 is a heap buffer over-read vulnerability in libheif's overlay image processing. Attackers can craft malicious HEIF files to trigger memory corruption, potentially causing crashes or inf...

CVE-2025-29482

MEDIUM CVSS 6.2 Apr 7, 2025

A buffer overflow vulnerability in libheif 1.19.7 allows local attackers to execute arbitrary code through SAO processing in libde265. This affects systems using libheif for HEIF/HEIC image processing...