Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4443-1 | dcmtk security update |
Tue, 24 Feb 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:* |
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Offis
Offis dcmtk |
|
| Vendors & Products |
Offis
Offis dcmtk |
Thu, 18 Dec 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null pointer dereference. The attack requires local access. Upgrading to version 3.7.0 is sufficient to resolve this issue. Patch name: ffb1a4a37d2c876e3feeb31df4930f2aed7fa030. You should upgrade the affected component. | |
| Title | OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference | |
| Weaknesses | CWE-404 CWE-476 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-24T05:53:27.564Z
Reserved: 2025-12-17T17:45:16.548Z
Link: CVE-2025-14841
Updated: 2025-12-18T14:47:26.375Z
Status : Deferred
Published: 2025-12-18T01:15:51.747
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-14841
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:55:30Z
Debian DLA