CVE-2025-9732
- EPSS 0.02%
- Veröffentlicht 31.08.2025 14:02:06
- Zuletzt bearbeitet 05.09.2025 20:21:46
A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img. Such manipulation leads to memory corruption. Local access is required to approa...
CVE-2025-2357
- EPSS 0.09%
- Veröffentlicht 17.03.2025 01:31:04
- Zuletzt bearbeitet 23.06.2025 15:11:50
A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The manipulation leads to memory corruption. The attack can be initiated remotely. The explo...
CVE-2024-52333
- EPSS 0.06%
- Veröffentlicht 13.01.2025 15:15:09
- Zuletzt bearbeitet 13.01.2025 16:15:17
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerabili...
CVE-2024-47796
- EPSS 0.05%
- Veröffentlicht 13.01.2025 15:15:08
- Zuletzt bearbeitet 24.06.2025 13:47:04
An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2024-27628
- EPSS 0.81%
- Veröffentlicht 28.06.2024 19:15:05
- Zuletzt bearbeitet 11.06.2025 15:22:56
Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.
CVE-2024-34509
- EPSS 0.11%
- Veröffentlicht 05.05.2024 20:15:07
- Zuletzt bearbeitet 11.06.2025 15:35:22
dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
CVE-2024-34508
- EPSS 0.06%
- Veröffentlicht 05.05.2024 20:15:07
- Zuletzt bearbeitet 10.06.2025 17:44:33
dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
CVE-2024-28130
- EPSS 0.11%
- Veröffentlicht 23.04.2024 15:15:49
- Zuletzt bearbeitet 27.06.2025 14:32:16
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to t...
CVE-2022-43272
- EPSS 0.11%
- Veröffentlicht 02.12.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:26:10
DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.
CVE-2021-41690
- EPSS 0.1%
- Veröffentlicht 28.06.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 06:26:38
DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are not freed properly. Sending specific requests to the dcmqrdb program can incur a memory leak....