CVE-2019-5092 is a critical heap out-of-bounds write vulnerability affecting the UI tag parsing functionality within the DICOM image format of LEADTOOLS 20.0.2019.3.15. A specially crafted DICOM image can cause data to be written beyond the allocated heap memory, potentially leading to arbitrary code execution. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk. It can be exploited remotely over the network with low attack complexity, requiring user interaction (e.g., opening a malicious DICOM image) to achieve high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.0.2019.3.15CPE matchmatch criteria | cpe:2.3:a:leadtools:leadtools:20.0.2019.3.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.