The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade libheif to version 1.23.1 or higher.
Affected versions of this package are vulnerable to Out-of-bounds Read in the Track::init_sample_timing_table process. An attacker can trigger a heap buffer overflow by providing a crafted file where the number of chunks defined in the stco box is less than the number of samples in stsz, leading to out-of-bounds access in the chunk vector during a call to heif_track_get_next_raw_sequence_sample.