CVE-2026-10194
OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
14th
A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. This patch is called 0f78a4ef6f645ea5530166e445e5436a5de58e75. A patch should be applied to remediate this issue.
| CWE | CWE-122 CWE-119 |
| Vendor | offis |
| Product | dcmtk |
| Published | May 31, 2026 |
| Last Updated | Jun 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for offis dcmtk
Be the first to know when new medium vulnerabilities affecting offis dcmtk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
OFFIS / DCMTK
3.7.0
References
Credits
elp3pinill0 ๐ dapickle (VulDB User)