hevc_video_extensions_from_device_manufacturer vulnerabilities
CVEs whose affected-version data names the hevc_video_extensions_from_device_manufacturer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-58600High· 7.8Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
▾ TwilightMicrosoft · HEVC Video ExtensionsEPSS 0.48%via NVD
CVE-2026-58599High· 7.8Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
▾ TwilightMicrosoft · HEVC Video ExtensionsEPSS 0.48%via NVD