CVE-2025-14841 is a null pointer dereference vulnerability in OFFIS DCMTK versions up to 3.6.9, specifically within the dcmqrdb/libsrc/dcmqrdbi.cc component. This flaw, requiring local access, results in a low-severity denial of service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Organizations should upgrade to DCMTK version 3.7.0 to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| OFFIS | DCMTK | 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.6.4, 3.6.5, 3.6.6, 3.6.7, 3.6.8, 3.6.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.