Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2026-88054

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88053

Medium priority

Some fixes available 5 of 7

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88052

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88051

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88050

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component....

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88049

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88048

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions....

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-88047

Medium priority
Fixed

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-73067

Medium priority

Some fixes available 5 of 7

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run,...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-73066

Medium priority
Fixed

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in...

1 affected package

tesseract

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tesseract Fixed Fixed Fixed Fixed Fixed
Show less packages