Microdicom develops a specialized DICOM medical-imaging viewer whose vulnerability exposure centers on memory-safety and authentication-handling issues, including out-of-bounds writes, heap-based buffer overflows, improper authorization in custom URL scheme handlers, and certificate validation weaknesses. The medical-imaging use case and the viewer's role in handling untrusted medical data files create a narrow but mission-critical attack surface. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microdicom over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36521HIGH MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM fil | May 1, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-35975HIGH MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation. | May 1, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-33606HIGH An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User inter | Jun 11, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-28877HIGH MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. User intera | Jun 11, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-25578HIGH
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within the appl | Mar 1, 2024 | 7.8 | 21 | NO | NO |
CVE-2024-22100HIGH
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary c | Mar 1, 2024 | 7.8 | 21 | NO | NO |
CVE-2025-1002MEDIUM MicroDicom DICOM Viewer version 2024.03
fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to | Feb 10, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microdicom.
Media articles that mention a CVE ID that affects a product developed by Microdicom — matched by CVE ID, not by vendor name.