Back to Database
Status published
High
CVE-2020-19499
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows...
Vulnerability Description
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-19499
Credits & Attribution
No credits recorded in the NVD database.
References
More from struktur
View All →CVE-2025-43967
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder...
Low
2.9
CVE-2025-43966
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden...
Low
2.9
CVE-2022-47665
Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int,...
Unknown
0
CVE-2022-47664
Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse...
Unknown
0
CVE-2022-47655
Libde265 1.0.9 is vulnerable to Buffer Overflow in function void...
Unknown
0
Affected Vendor
struktur
View all reports →Affected Software
libheif
Vulnerable Versions:
1.4.0
Timeline
Official Publish:
July 21st, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.