Leptonica is an image-processing library embedded across document-scanning, OCR, and archival software, where its critical role in parsing untrusted image formats creates a bounded but high-leverage attack surface. Vulnerabilities affecting the library skew toward critical-severity outcomes and recur through memory-safety and input-handling weakness classes such as out-of-bounds reads, path traversal, OS command injection, and race conditions that are characteristic of low-level image codec implementations. Defenders should monitor this vendor's releases closely wherever OCR or document-processing pipelines ingest untrusted image data; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leptonica over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7440CRITICAL An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exis | Feb 23, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-7247CRITICAL An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code | Feb 19, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-7186CRITICAL Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based | Feb 16, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7442CRITICAL An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversa | Feb 23, 2018 | 9.1 | 27 | NO | NO |
CVE-2020-36281HIGH Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. | Mar 12, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-36278HIGH Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c. | Mar 12, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-36277HIGH Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c. | Mar 11, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-36280HIGH Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c. | Mar 12, 2021 | 7.5 | 25 | NO | NO |
CVE-2020-36279HIGH Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c. | Mar 12, 2021 | 7.5 | 25 | NO | NO |
CVE-2018-3836HIGH An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection | Apr 24, 2018 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leptonica.
Media articles that mention a CVE ID that affects a product developed by Leptonica — matched by CVE ID, not by vendor name.