CVE-2019-5092: Leadtools
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image format of LEADTOOLS 20.0.2019.3.15. A specially crafted DICOM image can cause an offset beyond the bounds of a heap allocation to be written, potentially resulting in code execution. An attacker can specially craft a DICOM image to trigger this vulnerability.
Affected products
- Leadtools Leadtools: version 20.0.2019.3.15 only
Published 2019-12-12. Last modified 2026-06-17.