Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Malaterre

First CVE: Jan 12, 2016Active for: 11 yearsTotal CVEs: 9

Malaterre's vulnerability profile centers on Grassroots DICOM, a specialized medical imaging processing library that occupies a niche but critical role in healthcare software stacks. Despite the narrowly scoped product portfolio, the vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by the memory-intensive nature of DICOM parsing and the sensitivity of medical imaging workflows. Vulnerabilities recur through out-of-bounds read and write conditions and improper memory-buffer restrictions that reflect the low-level data-handling demands of image codecs. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Malaterre over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2016
10 years ago
Most Recent CVE
Dec 16, 2025
220 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-8396CRITICAL
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attacke
Jan 12, 201610.043NOYES
CVE-2025-53619CRITICAL
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak
Dec 16, 20259.132NONO
CVE-2024-22391CRITICAL
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead
Apr 25, 20249.830NONO
CVE-2025-53618CRITICAL
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak
Dec 16, 20259.129NONO
CVE-2025-48429CRITICAL
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An
Dec 16, 20259.129NONO
CVE-2025-52582HIGH
An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an informatio
Dec 16, 20257.526NONO
CVE-2024-22373CRITICAL
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file ca
Apr 25, 20249.826NONO
CVE-2015-8397HIGH
The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive info
Jan 12, 20168.223NONO
CVE-2024-25569MEDIUM
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out
Apr 25, 20246.519NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
22%
67%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Malaterre.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Malaterre — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Malaterre's Products

View all 2 CNAs →

Top CWEs