Search CVE reports


Toggle filters

301 – 310 of 48104 results

Status is adjusted based on your filters.


CVE-2026-84448

Medium priority
Vulnerable

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it...

1 affected package

libheif

Package 24.04 LTS
libheif Vulnerable
Show less packages

CVE-2026-84447

Medium priority
Vulnerable

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch...

1 affected package

libheif

Package 24.04 LTS
libheif Vulnerable
Show less packages

CVE-2026-84446

Medium priority
Not affected

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-84444

Medium priority
Not affected

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-84384

Medium priority
Vulnerable

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an...

1 affected package

libheif

Package 24.04 LTS
libheif Vulnerable
Show less packages

CVE-2026-84383

Medium priority
Not affected

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-75883

Medium priority
Needs evaluation

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without...

1 affected package

network-manager-l2tp

Package 24.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-67549

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec,...

1 affected package

openimageio

Package 24.04 LTS
openimageio Needs evaluation
Show less packages

CVE-2026-65970

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make...

1 affected package

openimageio

Package 24.04 LTS
openimageio Needs evaluation
Show less packages

CVE-2026-65969

Medium priority
Needs evaluation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that...

1 affected package

openimageio

Package 24.04 LTS
openimageio Needs evaluation
Show less packages