Leadtools is a vendor of document imaging and multimedia processing libraries widely embedded in enterprise applications and content-management systems, placing its small product footprint into a high-impact position across downstream deployments. Vulnerabilities affecting the vendor skew toward critical severity and recur through memory-safety weakness classes including out-of-bounds writes, heap-based buffer overflows, integer overflows and underflows, and improper input validation, typical of C/C++ media-parsing codebases that process untrusted files. Defenders should prioritize tracking and remediating Leadtools advisories in applications that ingest user-supplied documents or media, since a single flaw in the embedded library can affect all downstream products that link it; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leadtools over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5085CRITICAL An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause | Dec 12, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-5093CRITICAL An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can cause | Dec 12, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-5154HIGH An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A specially crafted J2K image file can cause an out of bounds w | Dec 12, 2019 | 8.8 | 27 | NO | NO |
CVE-2008-1605MEDIUM The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow at | Apr 1, 2008 | 6.8 | 27 | NO | YES |
CVE-2019-5125HIGH An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image file can cause an out of bounds write of a he | Nov 6, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5100HIGH An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A specially crafted BMP image file can cause an integer overflow, pote | Nov 6, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5099HIGH An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potential | Nov 6, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-5091HIGH An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so version 20.0.2019.3.15. A specially crafted packet can caus | Dec 12, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-5090HIGH An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet ca | Dec 12, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-5092HIGH An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image format of LEADTOOLS 20.0.2019.3.15. A specially crafted DICOM im | Dec 12, 2019 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leadtools.
Media articles that mention a CVE ID that affects a product developed by Leadtools — matched by CVE ID, not by vendor name.