Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/hyunjungg/CVE-2025-62821 |
|
Mon, 22 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
cvssV3_1
|
Fri, 19 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft heif Image Extension |
|
| Vendors & Products |
Microsoft
Microsoft heif Image Extension |
Fri, 19 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out-of-Bounds Read in Microsoft HEIF Image Extensions Facilitates Potential Memory Corruption | |
| Weaknesses | CWE-20 |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-22T17:16:13.925Z
Reserved: 2025-10-23T00:00:00.000Z
Link: CVE-2025-62821
Updated: 2026-06-22T15:43:38.721Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-22T19:30:06Z