CVE-2024-23912: Merative Merge Dicom Toolkit C/c++

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.

Affected products

  • Merative Merge Dicom Toolkit C/c++: from v5.0.0, up to and including v5.17.0
  • Merative Merge Dicom Toolkit C C\+\+: from v5.0.0, up to and including 5.17.0

Published 2024-05-03. Last modified 2026-06-17.