An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.
📦
heif
Vendor: nokia
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.32%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.5
CVSS
Severity: MEDIUM
7.8
CVSS
CVE-2021-32288
RCE
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
Severity: HIGH
7.8
CVSS
CVE-2021-32287
RCE
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
Severity: HIGH