CVE detail
CVE-2025-14841
A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null pointer dereference. The attack requires local access. Upgrading to version 3.7.0 is sufficient to resolve this issue. Patch name: ffb1a4a37d2c876e3feeb31df4930f2aed7fa030. You should upgrade the affected component.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/?submit.714634vuldb.com
No excerpt available.
Exploitvuldb.comDec 18, 2025, 1:15 AM - https://vuldb.com/?submit.714605vuldb.com
No excerpt available.
Exploitvuldb.comDec 18, 2025, 1:15 AM - https://vuldb.com/?id.337004vuldb.com
No excerpt available.
Exploitvuldb.comDec 18, 2025, 1:15 AM - https://vuldb.com/?ctiid.337004vuldb.com
No excerpt available.
Exploitvuldb.comDec 18, 2025, 1:15 AM - https://support.dcmtk.org/redmine/issues/1183support.dcmtk.org
No excerpt available.
Vendor Advisorysupport.dcmtk.orgDec 18, 2025, 1:15 AM No excerpt available.
Exploitgithub.comDec 18, 2025, 1:15 AMNo excerpt available.
Exploitgithub.comDec 18, 2025, 1:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-76014CVSS 1.9 · Low
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such m…
- CVE-2026-75013CVSS 5.7 · Medium
A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null p…
- CVE-2026-75012CVSS 5.7 · Medium
A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the…
- CVE-2026-17500CVSS 6.9 · Medium
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation result…
- CVE-2026-15690CVSS 1.3 · Low
A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the compo…
- CVE-2026-15184CVSS 1.9 · Low
A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a…