peter bassill · operator
$ cve CVE-2015-8396 JSON

CVE-2015-8396 EXPLOIT

10.0
CRITICAL · CVSS 3.0 · EPSS 16% (pctl 97)

Patch early

A public exploit exists.

Description

Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.

Scoring

CVSS10.0 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS16.03% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2016-01-12
Last modified2026-06-17

Affected (1)

VendorProduct
malaterregrassroots dicom

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD