OpenCV is a widely deployed computer-vision library that, despite maintaining a single focused product, reaches across an enormous range of applications spanning robotics, autonomous systems, medical imaging, surveillance, and scientific computing. The vendor's vulnerability footprint reflects the memory-safety and bounds-checking challenges inherent to image and video processing: recurring weakness classes include out-of-bounds reads and writes, buffer overflows, integer overflows, and reachable assertions that arise from the library's low-level pixel manipulation and codec parsing code. Because OpenCV is embedded as a dependency in countless downstream applications rather than deployed standalone, a single flaw can propagate across diverse and often long-lived consumer and industrial products that may not track upstream security updates. Defenders should inventory applications that depend on this library and treat OpenCV updates as supply-chain priorities; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opencv over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5063HIGH An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, | Jan 3, 2020 | 8.8 | 38 | NO | NO |
CVE-2019-5064HIGH An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a | Jan 3, 2020 | 8.8 | 31 | NO | NO |
CVE-2017-1000450HIGH In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, ma | Jan 2, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-12863HIGH In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from remote, may lead to remote code | Aug 15, 2017 | 8.8 | 29 | NO | NO |
CVE-2017-12606HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow4 in utils.cpp when reading an image file by using cv::imread. | Aug 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12605HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillColorRow8 function in utils.cpp when reading an image file by using cv::imread. | Aug 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12604HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillUniColor function in utils.cpp when reading an image file by using cv::imread. | Aug 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12603HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image | Aug 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12601HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image | Aug 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-12598HIGH OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when readin | Aug 7, 2017 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opencv.
Media articles that mention a CVE ID that affects a product developed by Opencv — matched by CVE ID, not by vendor name.