CVE-2025-2581
Last modified
CVE-2025-2581 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. The manipulation leads to integer underflow. The attack can be launched remotely. Upgrading to version 0.25.1 is able to address this issue. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmedcon Project | Xmedcon | 0.25.0 |
References
- https://vuldb.com/?ctiid.300541Permissions Required, VDB Entry
- https://vuldb.com/?id.300541Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.522216Third Party Advisory, VDB Entry
- https://xmedcon.sourceforge.io/Main/NewProduct, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-2581?
How severe is CVE-2025-2581?
How do I fix CVE-2025-2581?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-25796SeaCMS v13.3 was discovered to contain a remote code executi…5.1
- CVE-2025-25797SeaCMS v13.3 was discovered to contain a remote code executi…5.1
- CVE-2025-25799SeaCMS 13.3 was discovered to contain an arbitrary file read…6
- CVE-2025-2580The Contact Form by Bit Form plugin for WordPress is vulnera…4.9
- CVE-2025-25800SeaCMS 13.3 was discovered to contain an arbitrary file read…5.3
- CVE-2025-25802SeaCMS v13.3 was discovered to contain a remote code executi…5.1
- CVE-2025-25813SeaCMS v13.3 was discovered to contain a remote code executi…5.1
- CVE-2025-25818A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5…5.1
- CVE-2025-2582A vulnerability was found in SimpleMachines SMF 2.1.4 and cl…5.4
- CVE-2025-25823A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5…7.3
- CVE-2025-25825A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5…7.1
- CVE-2025-25827A Server-Side Request Forgery (SSRF) in the component sort.p…6.8
Are you affected by CVE-2025-2581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
