Medicomp maintains the Medcin Engine, a clinical knowledge and documentation product deployed within healthcare systems, with a focused vulnerability footprint centered on memory-buffer handling within that core offering. The observed weakness class reflects the complexity of managing structured clinical data and the memory-safety demands of the underlying codebase. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Medicomp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6006HIGH The AddUserFinding implementation in Medicomp MEDCIN Engine 2.22.20153.x before 2.22.20153.226 might allow remote attackers to execute arbitrary code or cause a denial of service ( | Oct 29, 2015 | 7.5 | 22 | NO | NO |
CVE-2015-2898MEDIUM Multiple stack-based buffer overflows in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, rela | Oct 29, 2015 | 6.8 | 20 | NO | NO |
CVE-2015-2901MEDIUM Multiple stack-based buffer overflows in Medicomp MEDCIN Engine 2.22.20142.166 might allow remote attackers to execute arbitrary code via a crafted packet on port 8190, related to | Oct 29, 2015 | 6.8 | 19 | NO | NO |
CVE-2015-2900MEDIUM The AddUserFinding add_userfinding2 function in Medicomp MEDCIN Engine before 2.22.20153.226 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly | Oct 29, 2015 | 6.8 | 19 | NO | NO |
CVE-2015-2899MEDIUM Heap-based buffer overflow in the QualifierList retrieve_qualifier_list function in Medicomp MEDCIN Engine before 2.22.20153.226 might allow remote attackers to execute arbitrary c | Oct 29, 2015 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Medicomp.
Media articles that mention a CVE ID that affects a product developed by Medicomp — matched by CVE ID, not by vendor name.