6.6
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
Basic Information
ID
CVE-2025-53644
Source
GitHub_M
Published
Jul 17, 2025 at 17:58
Modified
Aug 5, 2025 at 18:37
Affected Product
Vendor
opencv
Product
opencv
Version
< 4.12.0
Affected Versions
opencv opencv < 4.12.0