Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2025-2029

Disclosure Date: March 06, 2025 (last updated March 07, 2025)
A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. It has been classified as critical. Affected is an unknown function of the file mDicom.exe. The manipulation leads to memory corruption. The attack needs to be approached locally. It is recommended to upgrade the affected component. The vendor quickly confirmed the existence of the vulnerability and fixed it in the latest beta.
Attacker Value
Unknown

CVE-2025-1002

Disclosure Date: February 10, 2025 (last updated March 04, 2025)
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.
Attacker Value
Unknown

CVE-2024-33606

Disclosure Date: June 11, 2024 (last updated March 01, 2025)
An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-28877

Disclosure Date: June 11, 2024 (last updated March 01, 2025)
MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-25569

Disclosure Date: April 25, 2024 (last updated February 26, 2025)
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-22391

Disclosure Date: April 25, 2024 (last updated February 26, 2025)
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-22373

Disclosure Date: April 25, 2024 (last updated February 26, 2025)
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-25578

Disclosure Date: March 01, 2024 (last updated March 07, 2025)
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within the application.
Attacker Value
Unknown

CVE-2024-22100

Disclosure Date: March 01, 2024 (last updated March 07, 2025)
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. A user must open a malicious DCM file in order to exploit the vulnerability.
Attacker Value
Unknown

CVE-2020-35308

Disclosure Date: March 31, 2021 (last updated November 28, 2024)
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.