Libde265
66 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libde265, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Libde265 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 66 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High16
- Medium46
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Libde265.
- CVE-2026-54241libde265: SAO sequential filter heap buffer overflow via signed integer overflow7.4
- CVE-2026-54240libde265: Pixel accessor signed integer overflow causes heap OOB read/write7.4
- CVE-2026-45383libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18—
- CVE-2026-45382libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry—
- CVE-2026-49346libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow7.1
- CVE-2026-49295libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS7.1
- CVE-2026-49337libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`4.3
- CVE-2026-33164NULL Pointer Dereference in libde2657.5
- CVE-2026-33165heap out-of-bounds write in libde265 1.0.165.5
- CVE-2025-61147strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().6.2
- CVE-2024-38949Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc6.5
- CVE-2024-38950Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.6.5
- CVE-2023-51792Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.3.3
- CVE-2023-49468Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.8.8
- CVE-2023-49465Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.8.8
Product grouping is registry-driven, with AI assist and human review. How it works