CVE-2019-5063 describes a critical heap buffer overflow vulnerability in OpenCV 4.1.0, specifically within its data structure persistence functionality, affecting various Oracle products that integrate OpenCV. An attacker can exploit this by providing a specially crafted XML file, leading to multiple heap corruptions and potential remote code execution. This vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity, requiring user interaction (UI:R) but potentially resulting in high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not listed in CISA's KEV catalog, its high FAUCET Risk Score and notable community discussion and media coverage suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:opencv:opencv:4.1.0:*:*:*:*:*:*:* | ||
13.3.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* | ||
< 2.0CPE matchmatch criteria | cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:* | ||
13.4.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.