Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dcmtk CRITICAL 9.8
CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a…

Fix: after 3.7.0
Fix from $2,300 2026-04-06
Dcmtk MEDIUM 5.5
CVE-2022-4981

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc…

Fix: 3.6.8+
Fix from $1,600 2025-10-21
Dcmtk MEDIUM 5.5
CVE-2020-36855

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manip…

Fix: 3.6.6+
Fix from $1,600 2025-10-21
Dcmtk HIGH 7.8
CVE-2025-9732

A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of th…

Fix: after 3.6.9
Fix from $1,950 2025-08-31
Dcmtk MEDIUM 6.3
CVE-2025-2357

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS …

Mitigation only
Fix from $1,600 2025-03-17
Dcmtk HIGH 7.8
CVE-2024-52333

An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can…

Patch available
Fix from $1,950 2025-01-13
Dcmtk HIGH 7.8
CVE-2024-47796

An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead t…

Patch available
Fix from $1,950 2025-01-13
Dcmtk HIGH 8.1
CVE-2024-27628

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

Patch available
Fix from $1,950 2024-06-28
Dcmtk HIGH 7.5
CVE-2022-43272

DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.

Patch available
Fix from $1,950 2022-12-02
Dcmtk HIGH 7.5
CVE-2021-41687

DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsi…

Fix: after 3.6.6
Fix from $1,950 2022-06-28
Dcmtk HIGH 7.5
CVE-2021-41688

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending…

Fix: after 3.6.6
Fix from $1,950 2022-06-28
Dcmtk HIGH 7.5
CVE-2021-41689

DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the …

Fix: after 3.6.6
Fix from $1,950 2022-06-28
Dcmtk HIGH 7.5
CVE-2021-41690

DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST …

Fix: after 3.6.6
Fix from $1,950 2022-06-28
Dcmtk CRITICAL 9.8
CVE-2022-2119

OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files i…

Fix: 3.6.7+
Fix from $2,300 2022-06-24
Dcmtk CRITICAL 9.8
CVE-2022-2120

OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM fi…

Fix: 3.6.7+
Fix from $2,300 2022-06-24
Dcmtk MEDIUM 6.5
CVE-2022-2121

OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-o…

Fix: 3.6.7+
Fix from $1,600 2022-06-24
Dcmtk HIGH 7.2
CVE-2013-6825

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in d…

Fix: after 3.6.1
Fix from $1,950 2014-06-10