A heap-based buffer overflow vulnerability exists in MediaInfoLib version 26.01. A specially crafted media file with ID3v2 tags can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. This vulnerability is particularly concerning for defenders responsible for media file processing systems, developers using MediaInfoLib, and security teams assessing exp [truncated]
A heap-based buffer overflow vulnerability exists in MediaInfoLib version 26.01. A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. Defenders and administrators using MediaInfoLib 26.01 should assess exposure and prioritize verification of their environment. The LXF parsing functionality of MediaInfoLib 26.01 contains [truncated]
CVE-2026-28764 describes a heap-based buffer overflow in MediaArea MediaInfoLib’s LXF element parsing path. The supplied CVSS vector rates it HIGH with local access and user interaction required, and the impact is recorded as high across confidentiality, integrity, and availability.
CVE-2026-22554 is a high-severity heap-based buffer overflow in MediaArea MediaInfoLib’s channel splitting logic. The official NVD record cites a Talos CNA report and assigns a 7.8 CVSS score, with local access and user interaction required. Organizations that embed or ship MediaInfoLib should confirm whether they rely on affected builds and prioritize updates or compensating controls once vendor guidance [truncated]