cbcvebase.

Debian Opencv vulnerabilities

32 known vulnerabilities affecting debian/opencv.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM9LOW3

Vulnerabilities

Page 1 of 2
CVE-2025-53644MEDIUMCVSS 6.6fixed in opencv 3.2.0+dfsg-1 (bookworm)2025
CVE-2025-53644 [MEDIUM] CVE-2025-53644: opencv - OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 hav... OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-1) bullseye: resolved (fixed in 3.2.0+dfsg-1) forky: resolved (fixed i
debian
CVE-2023-2617MEDIUMCVSS 5.3fixed in opencv 4.6.0+dfsg-12 (bookworm)2023
CVE-2023-2617 [MEDIUM] CVE-2023-2617: opencv - A vulnerability classified as problematic was found in OpenCV wechat_qrcode Modu... A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is the function DecodedBitStreamParser::decodeByteSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the
debian
CVE-2023-2618MEDIUMCVSS 5.3fixed in opencv 4.6.0+dfsg-12 (bookworm)2023
CVE-2023-2618 [MEDIUM] CVE-2023-2618: opencv - A vulnerability, which was classified as problematic, has been found in OpenCV w... A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to memory leak. The attack may be launched remotely. The name of the patch is 2b62ff6181163ee
debian
CVE-2019-14491HIGHCVSS 8.2fixed in opencv 4.1.2+dfsg-3 (bookworm)2019
CVE-2019-14491 [HIGH] CVE-2019-14491: opencv - An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an... An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service. Scope: local bookworm: resolved (fixed in 4.1.2+dfsg-3) bullseye: resolved (fixed in 4.1.2+dfsg-3) forky: resolved (fixed in 4.1.2+dfsg-3) sid: resolved (fi
debian
CVE-2019-14493HIGHCVSS 7.5fixed in opencv 4.1.2+dfsg-3 (bookworm)2019
CVE-2019-14493 [HIGH] CVE-2019-14493: opencv - An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer derefere... An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp. Scope: local bookworm: resolved (fixed in 4.1.2+dfsg-3) bullseye: resolved (fixed in 4.1.2+dfsg-3) forky: resolved (fixed in 4.1.2+dfsg-3) sid: resolved (fixed in 4.1.2+dfsg-3) trixie: resolved (fixed in 4.1.2+d
debian
CVE-2019-14492HIGHCVSS 7.5fixed in opencv 4.1.2+dfsg-3 (bookworm)2019
CVE-2019-14492 [HIGH] CVE-2019-14492: opencv - An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an... An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::calc in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service. Scope: local bookworm: resolved (fixed in 4.1.2+dfsg-3) bullseye: resolved (fixed in 4.1.2+dfsg-3) forky: resolved (fixed in 4.1.2+dfsg-3
debian
CVE-2019-5063HIGHCVSS 8.8fixed in opencv 4.2.0+dfsg-3 (bookworm)2019
CVE-2019-5063 [HIGH] CVE-2019-5063: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p... An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in
debian
CVE-2019-5064HIGHCVSS 8.8fixed in opencv 4.2.0+dfsg-3 (bookworm)2019
CVE-2019-5064 [HIGH] CVE-2019-5064: opencv - An exploitable heap buffer overflow vulnerability exists in the data structure p... An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability. Scope: local bookworm:
debian
CVE-2019-15939MEDIUMCVSS 5.9fixed in opencv 4.1.2+dfsg-3 (bookworm)2019
CVE-2019-15939 [MEDIUM] CVE-2019-15939: opencv - An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::... An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp. Scope: local bookworm: resolved (fixed in 4.1.2+dfsg-3) bullseye: resolved (fixed in 4.1.2+dfsg-3) forky: resolved (fixed in 4.1.2+dfsg-3) sid: resolved (fixed in 4.1.2+dfsg-3) trixie: resolved (fixed in 4.1.2+dfsg-3)
debian
CVE-2019-19624MEDIUMCVSS 6.5fixed in opencv 4.1.2+dfsg-3 (bookworm)2019
CVE-2019-19624 [MEDIUM] CVE-2019-19624: opencv - An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, varia... An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing with small images, leading to an out-of-bounds read of the heap-allocated arrays Ux and Uy. Scope: local bookworm: res
debian
CVE-2019-16249LOWCVSS 5.32019
CVE-2019-16249 [MEDIUM] CVE-2019-16249: opencv - OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intri... OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in modules/video/src/dis_flow.cpp. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2018-5268MEDIUMCVSS 5.5fixed in opencv 3.2.0+dfsg-6 (bookworm)2018
CVE-2018-5268 [MEDIUM] CVE-2018-5268: opencv - In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::read... In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolved (fixed in 3.2.0+dfsg-6) sid: resolved (fixed in 3.2.0+dfsg-6) trixie: resolved (fix
debian
CVE-2018-5269MEDIUMCVSS 5.5fixed in opencv 3.2.0+dfsg-6 (bookworm)2018
CVE-2018-5269 [MEDIUM] CVE-2018-5269: opencv - In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modu... In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolved (fixed in 3.2.0+dfsg-6) sid: resolved (fixed in 3.2.0+dfsg-6) trixie: resolved (fixed in 3.2.0+dfsg-6)
debian
CVE-2017-12864HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12864 [HIGH] CVE-2017-12864: opencv - In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not check... In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolve
debian
CVE-2017-12862HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12862 [HIGH] CVE-2017-12862: opencv - In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is ... In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) fo
debian
CVE-2017-12599HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12599 [HIGH] CVE-2017-12599: opencv - OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds re... OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolved (fixed in 3.2.0+dfsg-6) sid: resolved (fixed in 3.2.0+dfsg-6) trixie: resolv
debian
CVE-2017-12601HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12601 [HIGH] CVE-2017-12601: opencv - OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow i... OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image file by using cv::imread, as demonstrated by the 4-buf-overflow-readData-memcpy test case. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6
debian
CVE-2017-12603HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12603 [HIGH] CVE-2017-12603: opencv - OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in... OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) fo
debian
CVE-2017-12597HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12597 [HIGH] CVE-2017-12597: opencv - OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds wr... OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolved (fixed in 3.2.0+dfsg-6) sid: resolved (fixed in 3.2.0+dfsg-6) trixie: res
debian
CVE-2017-12604HIGHCVSS 8.8fixed in opencv 3.2.0+dfsg-6 (bookworm)2017
CVE-2017-12604 [HIGH] CVE-2017-12604: opencv - OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds wr... OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillUniColor function in utils.cpp when reading an image file by using cv::imread. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-6) bullseye: resolved (fixed in 3.2.0+dfsg-6) forky: resolved (fixed in 3.2.0+dfsg-6) sid: resolved (fixed in 3.2.0+dfsg-6) trixie: reso
debian