CVE-2011-1136Medium· 4.7▾ SunlitIn tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
tesseract_ocr = 2.03tesseract_ocr = 2.04debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88053High· 7.8Tesseract is an open source OCR engine
CVE-2021-36081High· 7.8Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
CVE-2022-38266Medium· 6.5An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
CVE-2026-88052High· 7.8Tesseract is an open source OCR engine
CVE-2026-88054Medium· 5.5Tesseract is an open source OCR engine
CVE-2026-88047High· 7.8Tesseract is an open source OCR engine