Home/Product/opencv
Product

opencv

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-53644
>= 4.10.0 and < 4.12.0
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that
9.8CRITICAL
CVE-2023-2618
>= 4.5.2 and < 4.8.0
A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this
5.3MEDIUM
CVE-2023-2617
>= 4.5.2 and <= 4.7.0
A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is
5.3MEDIUM
CVE-2019-5064
>= 4.0.0 and < 4.2.0
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version
8.8HIGH
CVE-2019-5063
all versions
An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specia
8.8HIGH
CVE-2019-19624
< 4.1.1
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than o
6.5MEDIUM
CVE-2019-16249
all versions
OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in m
5.3MEDIUM
CVE-2019-15939
<= 4.1.0
An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdet
5.9MEDIUM
CVE-2019-14493
< 4.1.1
An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at module
7.5HIGH
CVE-2019-14492
< 3.4.7
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEval
7.5HIGH
CVE-2019-14491
< 3.4.7
An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrd
8.2HIGH
CVE-2018-7714
all versions
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denia
7.5HIGH
CVE-2018-7713
all versions
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denia
7.5HIGH
CVE-2018-7712
all versions
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denia
7.5HIGH
CVE-2018-5269
all versions
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorr
5.5MEDIUM
CVE-2018-5268
all versions
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg200
5.5MEDIUM
CVE-2017-1000450
<= 3.3.0
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to
8.8HIGH
CVE-2017-18009
all versions
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfm
7.5HIGH
CVE-2017-17760
all versions
OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is u
6.5MEDIUM
CVE-2017-14136
all versions
OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when
6.5MEDIUM
CVE-2017-12864
<= 3.3.0
In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overfl
8.8HIGH
CVE-2017-12863
<= 3.3.0
In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If
8.8HIGH
CVE-2017-12862
<= 3.3.0
In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer
8.8HIGH
CVE-2017-12606
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow4 in utils.c
8.8HIGH
CVE-2017-12605
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillColorRow8 function in utils.c
8.8HIGH
CVE-2017-12604
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the FillUniColor function in utils.cp
8.8HIGH
CVE-2017-12603
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in module
8.8HIGH
CVE-2017-12602
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has a denial of service (memory consumption) issue, as demonstrated by th
7.5HIGH
CVE-2017-12601
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules
8.8HIGH
CVE-2017-12600
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has a denial of service (CPU consumption) issue, as demonstrated by the 1
7.5HIGH
CVE-2017-12599
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R
8.8HIGH
CVE-2017-12598
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock functio
8.8HIGH
CVE-2017-12597
<= 3.3.0
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.c
8.8HIGH
CVE-2016-1517
all versions
OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
5.5MEDIUM
CVE-2016-1516
all versions
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin