CVE-2024-23913: Merative Merge Dicom Toolkit C/c++

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Message() function is used to read a malformed DICOM XML file, it might result in memory access violation.

Affected products

  • Merative Merge Dicom Toolkit C/c++: from v5.0.0, up to and including v5.17.0

Published 2024-05-03. Last modified 2026-06-17.