No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle
Oracle diagnostics |
|
| CPEs | cpe:2.3:a:oracle:diagnostics:8.5.19.75:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle diagnostics |
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Title | NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-28T01:46:36.954Z
Reserved: 2025-12-24T14:28:02.435Z
Link: CVE-2018-25142
Updated: 2025-12-24T20:12:17.268Z
Status : Deferred
Published: 2025-12-24T20:15:48.430
Modified: 2026-06-17T01:54:48.563
Link: CVE-2018-25142
No data.
OpenCVE Enrichment
No data.
-
CWE-611
Improper Restriction of XML External Entity Reference