Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Title | NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:25:54.871Z
Reserved: 2025-12-24T14:28:02.435Z
Link: CVE-2018-25142
Updated: 2025-12-24T20:12:17.268Z
Status : Awaiting Analysis
Published: 2025-12-24T20:15:48.430
Modified: 2025-12-29T15:58:13.147
Link: CVE-2018-25142
No data.
OpenCVE Enrichment
No data.