An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32287.json"