leptonica CVE Vulnerabilities & CVE List (13)

Products (CPE): — CVEs: 13

leptonica vulnerability overview

Aggregates CVE and security vulnerability intelligence across all leptonica-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk buffer overflow, vendor risk path handling, and vendor risk memory corruption, with potential vendor impact application crash across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 113 of 13 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-38266 An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file. [email protected] 6.5 0.26% 2022-09-09 2024-11-21
CVE-2020-36281 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. [email protected] 7.5 0.51% 2021-03-12 2024-11-21
CVE-2020-36280 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. [email protected] 7.5 1.75% 2021-03-12 2024-11-21
CVE-2020-36279 Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. [email protected] 7.5 4.25% 2021-03-12 2024-11-21
CVE-2020-36278 Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. [email protected] 7.5 0.54% 2021-03-12 2024-11-21
CVE-2020-36277 Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. [email protected] 7.5 4.00% 2021-03-11 2024-11-21
CVE-2018-3836 An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability. [email protected] 7.8 0.10% 2018-04-24 2024-11-21
CVE-2018-7442 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite. [email protected] 9.1 0.19% 2018-02-23 2024-11-21
CVE-2018-7441 Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c. [email protected] 7.0 0.04% 2018-02-23 2024-11-21
CVE-2018-7440 An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836. [email protected] 9.8 1.79% 2018-02-23 2024-11-21
CVE-2017-18196 Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif. [email protected] 3.3 0.04% 2018-02-23 2024-11-21
CVE-2018-7247 An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact. [email protected] 9.8 0.39% 2018-02-19 2024-11-21
CVE-2018-7186 Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions. [email protected] 9.8 3.12% 2018-02-16 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence