← Vulnerability feed

Vulnerability record · CVE-2019-5064 · published 3 January 2020

CVE-2019-5064: Opencv classic buffer overflow vulnerability

Opencv · Opencv

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

8.8 CVSS 3.1 High EPSS 11% · top 4.3% CWE-120 · Classic buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5064 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.9CVE-2026-46854Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Target Management). Supported versions …EPSS 0.43%9.9CVE-2026-46855Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions th…EPSS 0.43%9.9CVE-2026-46852Oracle enterprise manager base platform improper privilege management vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions th…EPSS 0.43%9.9CVE-2026-46832Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported version…EPSS 0.43%9.8CVE-2026-46994Oracle enterprise manager base platform improper access control vulnerabilityVulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions tha…EPSS 0.51%9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2019-5064), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.