VulnSea

tesseract_ocr vulnerabilities

CVEs whose affected-version data names the tesseract_ocr package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-88053High· 7.8PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .trainedda…

Midnighttesseract-ocr · tesseract_ocrEPSS 0.12%via NVD
CVE-2026-88052High· 7.8
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. u…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.13%via NVD
CVE-2026-88054Medium· 5.5PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED laye…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-88047High· 7.8
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.11%via NVD
CVE-2026-88051High· 7.8PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a c…

Midnighttesseract-ocr · tesseract_ocrEPSS 0.12%via NVD
CVE-2026-88049Medium· 5.5PoC⚖ disputed
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStep…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-88048High· 7.1PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During Fu…

Midnighttesseract-ocr · tesseract_ocrEPSS 0.11%via NVD
CVE-2026-88050Medium· 5.5PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCo…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2022-38266Medium· 6.5
4y ago

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

Sunlittesseract-ocr · tesseract_ocrEPSS 1.4%via NVD
CVE-2021-36081High· 7.8
5y ago

Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.

Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.

Twilighttesseract-ocr · tesseract_ocrEPSS 0.89%via NVD
CVE-2011-1136Medium· 4.7
6y ago

In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

Sunlittesseract-ocr · tesseract_ocrEPSS 0.45%via NVD
tesseract_ocr vulnerabilities (CVEs) · VulnSea