dcmtk
by Debian
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-52868 | Hig | 0.00 | 8.2 | 0.00 | Jun 30, 2026 | An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation. | ||
| CVE-2026-50254 | Hig | 0.00 | 7.5 | 0.01 | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator… | ||
| CVE-2026-50003 | Cri | 0.00 | 9.8 | 0.01 | Jun 30, 2026 | A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths. | ||
| CVE-2026-35505 | Hig | 0.00 | 7.5 | 0.01 | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart. | ||
| CVE-2026-44628 | Hig | 0.00 | 7.5 | 0.01 | Jun 30, 2026 | An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. |
- risk 0.00cvss 8.2epss 0.00
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.
- risk 0.00cvss 7.5epss 0.01
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator…
- risk 0.00cvss 9.8epss 0.01
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
- risk 0.00cvss 7.5epss 0.01
An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.
- risk 0.00cvss 7.5epss 0.01
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.