Show filters
260 Total Results
Displaying 21-30 of 260
Sort by:
Attacker Value
Unknown

CVE-2023-24754

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Attacker Value
Unknown

CVE-2023-24752

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Attacker Value
Unknown

CVE-2023-24751

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.
Attacker Value
Unknown

CVE-2023-24998

Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
Attacker Value
Unknown

CVE-2022-47655

Disclosure Date: January 05, 2023 (last updated February 24, 2025)
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>
Attacker Value
Unknown

CVE-2022-35256

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
Attacker Value
Unknown

CVE-2022-35255

Disclosure Date: December 05, 2022 (last updated February 24, 2025)
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.
Attacker Value
Unknown

CVE-2022-43245

Disclosure Date: November 02, 2022 (last updated December 22, 2024)
Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned short> in sao.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Attacker Value
Unknown

CVE-2022-43242

Disclosure Date: November 02, 2022 (last updated February 24, 2025)
Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma<unsigned char> in motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.
Attacker Value
Unknown

CVE-2022-43238

Disclosure Date: November 02, 2022 (last updated December 22, 2024)
Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted video file.