Vulnerabilities > Leptonica > High

DATE CVE VULNERABILITY TITLE RISK
2021-03-12 CVE-2020-36281 Out-of-bounds Read vulnerability in multiple products
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
network
low complexity
leptonica debian fedoraproject CWE-125
7.5
2021-03-12 CVE-2020-36280 Out-of-bounds Read vulnerability in multiple products
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
network
low complexity
leptonica fedoraproject CWE-125
7.5
2021-03-12 CVE-2020-36279 Out-of-bounds Read vulnerability in multiple products
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
network
low complexity
leptonica fedoraproject debian CWE-125
7.5
2021-03-12 CVE-2020-36278 Out-of-bounds Read vulnerability in multiple products
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
network
low complexity
leptonica fedoraproject debian CWE-125
7.5
2021-03-11 CVE-2020-36277 Always-Incorrect Control Flow Implementation vulnerability in multiple products
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
network
low complexity
leptonica fedoraproject debian CWE-670
7.5
2018-04-24 CVE-2018-3836 OS Command Injection vulnerability in multiple products
An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4.
local
low complexity
leptonica debian CWE-78
7.8
2018-02-23 CVE-2018-7441 Race Condition vulnerability in Leptonica
Leptonica through 1.75.3 uses hardcoded /tmp pathnames, which might allow local users to overwrite arbitrary files or have unspecified other impact by creating files in advance or winning a race condition, as demonstrated by /tmp/junk_split_image.ps in prog/splitimage2pdf.c.
local
high complexity
leptonica CWE-362
7.0