Tesseract-ocr
Tesseract-ocr Tesseract OCR: vulnerabilidades y CVE
Tesseract-ocr Tesseract OCR tiene 11 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88054 | Media (6.9) | 0.15% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL,… |
| CVE-2026-88053 | Alta (8.6) | 0.18% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a… |
| CVE-2026-88052 | Alta (7.8) | 0.18% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the… |
| CVE-2026-88051 | Alta (8.6) | 0.17% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata… |
| CVE-2026-88050 | Media (6.9) | 0.15% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder… |
| CVE-2026-88049 | Alta (8.6) | 0.15% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left… |
| CVE-2026-88048 | Alta (8.6) | 0.17% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix… |
| CVE-2026-88047 | Alta (8.6) | 0.11% | — | 10 sept 2026 | Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*)… |
| CVE-2022-38266 | Media (6.5) | 1.4% | — | 9 sept 2022 | An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file. |
| CVE-2021-36081 | Alta (7.8) | 0.89% | — | 1 jul 2021 | Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. |
| CVE-2011-1136 | Media (4.7) | 0.46% | — | 14 nov 2019 | In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.