A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. This patch is called 0f78a4ef6f645ea5530166e445e5436a5de58e75. A patch should be applied to remediate this issue.
Metrics
Affected Vendors & Products
References
History
Sun, 31 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. This patch is called 0f78a4ef6f645ea5530166e445e5436a5de58e75. A patch should be applied to remediate this issue. | |
| Title | OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow | |
| First Time appeared |
Offis
Offis dcmtk |
|
| Weaknesses | CWE-119 CWE-122 |
|
| CPEs | cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Offis
Offis dcmtk |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-31T16:30:08.129Z
Reserved: 2026-05-30T18:06:04.049Z
Link: CVE-2026-10194
No data.
Status : Received
Published: 2026-05-31T17:16:31.577
Modified: 2026-05-31T17:16:31.577
Link: CVE-2026-10194
No data.
OpenCVE Enrichment
No data.