Threats Tagged 'cve-2026-50142'
View all threats tagged with 'cve-2026-50142'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-50142'
Click on any threat for detailed analysis and mitigation recommendations
A high-severity integer overflow vulnerability exists in libheif versions 1.19.0 through 1.22.999, affecting the parsing of HEIF sequences with the msf1 brand. The flaw allows crafted input to cause unbounded heap allocation due to improper bounds checking and 32-bit arithmetic wraparound, potentially leading to memory exhaustion and process crashes. This issue is fixed in version 1.23.0. Join the discussion | CVE Database V5 | 08/18/2026, 21:18:03 UTC Added: 08/18/2026, 21:35:07 UTC |
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue. Join the discussion | CVE Database V5 | 06/19/2026, 17:16:20 UTC Added: 06/19/2026, 18:37:16 UTC |
0 Multiple security vulnerabilities have been addressed in libheif with the release of version 1.23.0. These include heap buffer over-reads, out-of-bounds reads and writes, integer overflows, infinite loop denial-of-service, null pointer dereferences, and information disclosure issues. The vulnerabilities arise from malformed or crafted HEIF image files and affect various components such as overlay compositing, sample duration lookup, mask image decoding, and metadata parsing. The update also includes new API functions and other feature enhancements. Join the discussion | GCVE Database | 06/17/2026, 08:37:36 UTC Added: 09/17/2026, 01:59:23 UTC |
Showing 1 to 3 of 3 results