VendorsTesseract-ocrtesseract_ocrall versions
Vulnerabilities

Tesseract-ocr Tesseract Ocr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-88051
Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields
Published 2026-09-10 · Analyzed
8.6EPSS 0.002
CVE-2026-88053
Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddata
Published 2026-09-10 · Analyzed
8.6EPSS 0.002
CVE-2026-88047
Tesseract: ReadNormProtos stack buffer overflow
Published 2026-09-10 · Analyzed
8.6EPSS 0.002
CVE-2026-88048
Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch
Published 2026-09-10 · Analyzed
8.6EPSS 0.002
CVE-2026-88049
Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch
Published 2026-09-10 · Analyzed
8.6EPSS 0.001
CVE-2021-36081
Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.
Published 2021-07-01 · Modified
7.8EPSS 0.009
CVE-2026-88052
Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization
Published 2026-09-10 · Analyzed
7.8EPSS 0.002
CVE-2026-88054
Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load
Published 2026-09-10 · Analyzed
6.9EPSS 0.002
CVE-2026-88050
Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
Published 2026-09-10 · Analyzed
6.9EPSS 0.001
CVE-2022-38266
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
Published 2022-09-09 · Modified
6.5EPSS 0.014
CVE-2011-1136
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
Published 2019-11-14 · Modified
6.3EPSS 0.005