Malaterre's vulnerability profile centers on Grassroots DICOM, a specialized medical imaging processing library that occupies a niche but critical role in healthcare software stacks. Despite the narrowly scoped product portfolio, the vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by the memory-intensive nature of DICOM parsing and the sensitivity of medical imaging workflows. Vulnerabilities recur through out-of-bounds read and write conditions and improper memory-buffer restrictions that reflect the low-level data-handling demands of image codecs. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Malaterre over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-8396CRITICAL Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attacke | Jan 12, 2016 | 10.0 | 43 | NO | YES |
CVE-2025-53619CRITICAL An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak | Dec 16, 2025 | 9.1 | 32 | NO | NO |
CVE-2024-22391CRITICAL A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead | Apr 25, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-53618CRITICAL An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak | Dec 16, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-48429CRITICAL An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An | Dec 16, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-52582HIGH An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an informatio | Dec 16, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-22373CRITICAL An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file ca | Apr 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2015-8397HIGH The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive info | Jan 12, 2016 | 8.2 | 23 | NO | NO |
CVE-2024-25569MEDIUM An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out | Apr 25, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Malaterre.
Media articles that mention a CVE ID that affects a product developed by Malaterre — matched by CVE ID, not by vendor name.