Offis / Dcmtk
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-97059 | DCMTK through 3.7.0 Heap Over-read via NumberOfFrames | HIGH | 8.8 | Sep 24, 2026 |
| CVE-2026-12805 | OFFIS DCMTK ofxml.cc parseFile heap-based overflow | MEDIUM | 5.3 | Jun 21, 2026 |
| CVE-2026-10194 | OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow | MEDIUM | 5.3 | May 31, 2026 |
| CVE-2026-5663 | OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection | MEDIUM | 6.9 | Apr 6, 2026 |
| CVE-2025-14841 | OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference | MEDIUM | 4.8 | Dec 18, 2025 |
| CVE-2025-14607 | OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption | MEDIUM | 5.3 | Dec 13, 2025 |
| CVE-2022-4981 | DCMTK dcmqrscp dcmqrcnf.cc readPeerList null pointer dereference | MEDIUM | 4.8 | Oct 21, 2025 |
| CVE-2020-36855 | DCMTK dcmqrscp parseQuota stack-based overflow | MEDIUM | 4.8 | Oct 21, 2025 |
| CVE-2025-9732 | DCMTK dcm2img diybrpxt.h memory corruption | MEDIUM | 4.8 | Aug 31, 2025 |
| CVE-2025-2357 | DCMTK dcmjpls JPEG-LS Decoder memory corruption | MEDIUM | 5.3 | Mar 17, 2025 |
| CVE-2025-25475 | dcmtk: NULL Pointer Dereference in DCMTK dcrleccd.cc Leading to DoS | HIGH | 7.5 | Feb 18, 2025 |
| CVE-2025-25474 | dcmtk: Buffer Overflow in DCMTK's diinpxt.h Component | HIGH | 7.4 | Feb 18, 2025 |
| CVE-2025-25472 | dcmtk: Buffer Overflow in DCMTK Leading to DoS | HIGH | 7.4 | Feb 18, 2025 |
| CVE-2024-52333 | An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to a… | HIGH | 8.4 | Jan 13, 2025 |
| CVE-2024-47796 | An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-o… | HIGH | 8.4 | Jan 13, 2025 |
| CVE-2024-27628 | Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component. | HIGH | 8.1 | Jun 28, 2024 |
| CVE-2024-34509 | dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message. | MEDIUM | 5.3 | May 5, 2024 |
| CVE-2024-34508 | dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message. | MEDIUM | 4.3 | May 5, 2024 |
| CVE-2024-28130 | An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malform… | HIGH | 7.5 | Apr 23, 2024 |
| CVE-2022-43272 | DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object. | HIGH | 7.5 | Dec 2, 2022 |
| CVE-2021-41687 | DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sendin… | HIGH | 7.5 | Jun 28, 2022 |
| CVE-2021-41688 | DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific… | HIGH | 7.5 | Jun 28, 2022 |
| CVE-2021-41690 | DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are no… | HIGH | 7.5 | Jun 28, 2022 |
| CVE-2021-41689 | DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result eve… | HIGH | 7.5 | Jun 28, 2022 |
| CVE-2022-2119 | OFFIS DCMTK Path Traversal | CRITICAL | 9.8 | Jun 24, 2022 |
Showing 1 to 24 of 24 CVEs