Offis

Dcmtk

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 30.06.2026 21:09:46
  • Zuletzt bearbeitet 01.07.2026 18:17:31

An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.

  • EPSS 0.41%
  • Veröffentlicht 30.06.2026 21:06:36
  • Zuletzt bearbeitet 01.07.2026 18:17:31

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

  • EPSS 0.43%
  • Veröffentlicht 30.06.2026 20:54:35
  • Zuletzt bearbeitet 01.07.2026 18:17:31

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 21.06.2026 19:15:07
  • Zuletzt bearbeitet 23.06.2026 14:17:22

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. ...

  • EPSS 0.25%
  • Veröffentlicht 31.05.2026 16:30:08
  • Zuletzt bearbeitet 22.07.2026 07:10:00

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based b...

  • EPSS 1.72%
  • Veröffentlicht 06.04.2026 14:15:11
  • Zuletzt bearbeitet 27.04.2026 18:43:25

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection....

  • EPSS 0.13%
  • Veröffentlicht 18.12.2025 00:02:08
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the compon...

  • EPSS 0.27%
  • Veröffentlicht 13.12.2025 13:02:07
  • Zuletzt bearbeitet 07.10.2026 19:10:00

A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The att...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.10.2025 15:15:37
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The attack needs to...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 21.10.2025 15:15:36
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stack-based buffer overflow. Local access is required t...