CVE-2018-25279
jiNa OCR Image to Text 1.0 Denial of Service via PNG
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the application by processing a malformed PNG file. Attackers can create a specially crafted PNG file with an oversized buffer and trigger the crash when the application attempts to convert the file to PDF.
| CWE | CWE-789 |
| Vendor | convertimagetotext |
| Product | jina ocr image to text |
| Published | Apr 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for convertimagetotext jina ocr image to text
Be the first to know when new medium vulnerabilities affecting convertimagetotext jina ocr image to text are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Convertimagetotext / jiNa OCR Image to Text
1.0
References
Credits
Gionathan "John" Reale