Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.15% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 16/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During LSTMRecognizer initialization in… | |
| Analizada | Alta (8.6) | 0.18% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 16/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .traineddata file and uses those values as loop bounds without validating them against… | |
| Analizada | Alta (7.8) | 0.18% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 16/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can leave the vector unchanged for an empty,… | |
| Analizada | Alta (8.6) | 0.17% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 16/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an invariant check. reserve(reserved) allocates the backing array, but the… | |
| Analizada | Media (6.9) | 0.15% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 14/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in src/ccutil/unicharcompress.cpp can consequently… | |
| Analizada | Alta (8.6) | 0.15% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 14/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart unchecked. In LSTM::Forward in… | |
| Analizada | Alta (8.6) | 0.17% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 14/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes… | |
| Analizada | Alta (8.6) | 0.11% | — | Tesseract-ocr Tesseract OCR | 10/9/2026 | 14/9/2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream… | |
| Analizada | Crítica (9.8) | 2.6% | — | Zapolnoch Tesseract OCR | 25/3/2026 | 17/6/2026 | node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper… | |
| Modificada | Media (6.5) | 1.4% | — | Tesseract-ocr Tesseract OCRLeptonicaDebian Linux | 9/9/2022 | 14/9/2026 | An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file. | |
| Modificada | Alta (7.8) | 0.89% | — | Tesseract-ocr Tesseract OCR | 1/7/2021 | 14/9/2026 | Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. | |
| Modificada | Media (4.7) | 0.46% | — | Tesseract-ocr Tesseract OCRDebian Linux | 14/11/2019 | 14/9/2026 | In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file. |