Known Vulnerabilities for products from Leptonica

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Leptonica".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-38266 json An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of S... 6.5 - MEDIUM 2022-09-09 2023-12-18
CVE-2020-36281 json Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. 7.5 - HIGH 2021-03-12 2023-11-07
CVE-2020-36280 json Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. 7.5 - HIGH 2021-03-12 2023-11-07
CVE-2020-36279 json Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. 7.5 - HIGH 2021-03-12 2023-11-07
CVE-2020-36278 json Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. 7.5 - HIGH 2021-03-12 2023-11-07
CVE-2020-36277 json Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixco... 7.5 - HIGH 2021-03-11 2023-11-07
CVE-2018-7442 json An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot ... 9.1 - CRITICAL 2018-02-23 2023-12-18
CVE-2018-7441 json Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have un... 7 - HIGH 2018-02-23 2023-12-18
CVE-2018-7440 json An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) a... 9.8 - CRITICAL 2018-02-23 2023-12-18
CVE-2018-7247 json An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can ov... 9.8 - CRITICAL 2018-02-19 2023-12-18
CVE-2018-7186 json Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows rem... 9.8 - CRITICAL 2018-02-16 2023-12-18
CVE-2018-3836 json An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafte... 7.8 - HIGH 2018-04-24 2023-02-03
CVE-2017-18196 json Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subd... 3.3 - LOW 2018-02-23 2023-12-18

Known software with vulnerabilities from Leptonica

Type Vendor Product Version
ApplicationLeptonicaLeptonica1.42

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report