CVE-2026-44038
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:13
- Zuletzt bearbeitet 08.10.2026 21:10:00
A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrec...
CVE-2026-44037
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:12
- Zuletzt bearbeitet 08.10.2026 21:10:00
Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion...
CVE-2026-44036
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:11
- Zuletzt bearbeitet 08.10.2026 21:10:00
Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exh...
CVE-2026-44035
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:10
- Zuletzt bearbeitet 08.10.2026 21:10:00
Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequen...
CVE-2026-44034
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:09
- Zuletzt bearbeitet 08.10.2026 21:10:00
A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose p...
CVE-2026-44033
- EPSS 0.11%
- Veröffentlicht 08.10.2026 12:55:08
- Zuletzt bearbeitet 08.10.2026 21:10:00
Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted...
CVE-2026-44031
- EPSS 0.39%
- Veröffentlicht 08.10.2026 12:55:01
- Zuletzt bearbeitet 08.10.2026 21:10:00
Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset conta...
CVE-2026-97059
- EPSS 0.35%
- Veröffentlicht 24.09.2026 13:52:00
- Zuletzt bearbeitet 30.09.2026 21:17:19
DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declari...
CVE-2026-50003
- EPSS 0.5%
- Veröffentlicht 30.06.2026 21:27:42
- Zuletzt bearbeitet 01.07.2026 18:17:31
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
CVE-2026-50254
- EPSS 0.42%
- Veröffentlicht 30.06.2026 21:14:01
- Zuletzt bearbeitet 01.07.2026 18:17:31
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting ...