CVE-2026-88054
- EPSS 0.18%
- Veröffentlicht 10.09.2026 17:39:54
- Zuletzt bearbeitet 16.09.2026 16:14:01
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a craft...
CVE-2026-88053
- EPSS 0.12%
- Veröffentlicht 10.09.2026 17:38:58
- Zuletzt bearbeitet 16.09.2026 16:14:31
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .traineddata file and u...
CVE-2026-88052
- EPSS 0.12%
- Veröffentlicht 10.09.2026 17:38:04
- Zuletzt bearbeitet 16.09.2026 16:21:10
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert...
CVE-2026-88051
- EPSS 0.12%
- Veröffentlicht 10.09.2026 17:37:01
- Zuletzt bearbeitet 16.09.2026 16:29:47
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an inva...
CVE-2026-88050
- EPSS 0.19%
- Veröffentlicht 10.09.2026 16:24:21
- Zuletzt bearbeitet 14.09.2026 20:02:01
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::Compu...
CVE-2026-88049
- EPSS 0.19%
- Veröffentlicht 10.09.2026 16:23:18
- Zuletzt bearbeitet 14.09.2026 20:01:48
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and Netw...
CVE-2026-88048
- EPSS 0.13%
- Veröffentlicht 10.09.2026 16:21:57
- Zuletzt bearbeitet 14.09.2026 20:01:33
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected:...
CVE-2026-88047
- EPSS 0.13%
- Veröffentlicht 10.09.2026 16:18:01
- Zuletzt bearbeitet 14.09.2026 20:01:21
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimi...
CVE-2022-38266
- EPSS 1.15%
- Veröffentlicht 09.09.2022 22:15:08
- Zuletzt bearbeitet 14.09.2026 14:10:44
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
CVE-2021-36081
- EPSS 0.89%
- Veröffentlicht 01.07.2021 03:15:08
- Zuletzt bearbeitet 14.09.2026 14:14:21
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.