CVE-2024-38949

EUVD-2024-37680
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
strukturlibde265
1.0.15
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libde265
bookworm
postponed
bullseye
no-dsa
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libde265
bionic
deferred
focal
deferred
jammy
deferred
mantic
ignored
noble
deferred
oracular
ignored
plucky
deferred
questing
deferred
xenial
deferred