Search maintains a narrowly scoped vulnerability footprint centered on the docconv document-conversion utility, with the durable signal reflecting OS command injection and excessive memory allocation issues that arise in data-processing and parsing contexts. Treat this as a focused vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Search over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4643CRITICAL A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulatio | Dec 21, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-4741MEDIUM A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertDocx/ConvertODT/ConvertPages/ConvertXML/XMLToText. The manipu | Dec 25, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Search.
Media articles that mention a CVE ID that affects a product developed by Search — matched by CVE ID, not by vendor name.