Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Leadtools

First CVE: Apr 1, 2008Active for: 18 yearsTotal CVEs: 13
55.3
VTI Score
TOP TARGET

Leadtools is a vendor of document imaging and multimedia processing libraries widely embedded in enterprise applications and content-management systems, placing its small product footprint into a high-impact position across downstream deployments. Vulnerabilities affecting the vendor skew toward critical severity and recur through memory-safety weakness classes including out-of-bounds writes, heap-based buffer overflows, integer overflows and underflows, and improper input validation, typical of C/C++ media-parsing codebases that process untrusted files. Defenders should prioritize tracking and remediating Leadtools advisories in applications that ingest user-supplied documents or media, since a single flaw in the embedded library can affect all downstream products that link it; current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Leadtools over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2008
18 years ago
Most Recent CVE
Apr 14, 2022
1,562 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5085CRITICAL
An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause
Dec 12, 20199.829NONO
CVE-2019-5093CRITICAL
An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause
Dec 12, 20199.828NONO
CVE-2019-5154HIGH
An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A specially crafted J2K image file can cause an out of bounds w
Dec 12, 20198.827NONO
CVE-2008-1605MEDIUM
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow at
Apr 1, 20086.827NOYES
CVE-2019-5125HIGH
An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a he
Nov 6, 20197.824NONO
CVE-2019-5100HIGH
An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A specially crafted BMP image file can cause an integer overflow, pote
Nov 6, 20197.824NONO
CVE-2019-5099HIGH
An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potential
Nov 6, 20197.824NONO
CVE-2019-5091HIGH
An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can caus
Dec 12, 20197.523NONO
CVE-2019-5090HIGH
An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet ca
Dec 12, 20197.523NONO
CVE-2019-5092HIGH
An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image format of LEADTOOLS 20.0.2019.3.15. A specially crafted DICOM im
Dec 12, 20198.822NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (46.2%)
Network6 (46.2%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High0 (0.0%)
Unknown1 (7.7%)
User Interaction
None4 (30.8%)
Unknown1 (7.7%)
Required8 (61.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None12 (92.3%)
Unknown1 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Leadtools.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Leadtools — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Leadtools's Products

View all 2 CNAs →

Top CWEs