NIH's vulnerability profile centers on a small set of widely embedded research and bioinformatics tools, including libzip, the NCBI Toolbox, and libdicom libraries that are integrated into scientific software and medical imaging workflows across academic and healthcare institutions. The vendor's disclosures skew toward critical-severity outcomes and frequently acquire public exploit code, with recurring memory-safety and input-handling weaknesses including use-after-free conditions, path traversal, cross-site scripting, buffer-boundary violations, and out-of-bounds writes that are characteristic of C and C++ codebases. Defenders should prioritize patches for these libraries given their distribution in research and medical environments and the exploit availability for disclosed flaws; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nih over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16716CRITICAL A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significan | May 2, 2019 | 9.1 | 43 | NO | YES |
CVE-2015-2331HIGH Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x befor | Mar 30, 2015 | 7.5 | 34 | NO | NO |
CVE-2018-16717CRITICAL A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. | May 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-24794CRITICAL A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing | Feb 20, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-24793CRITICAL A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing | Feb 20, 2024 | 9.8 | 26 | NO | NO |
CVE-2012-1162HIGH Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute | Jul 12, 2012 | 7.5 | 25 | NO | NO |
CVE-2012-1163MEDIUM Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directo | Jul 12, 2012 | 6.8 | 23 | NO | NO |
CVE-2018-16718MEDIUM An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument. | May 2, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nih.
Media articles that mention a CVE ID that affects a product developed by Nih — matched by CVE ID, not by vendor name.