Santesoft Sante DICOM Viewer Pro drew two advisories in three months. ICSMA-25-079-01 in March, an out-of-bounds write, CVE-2025-2480 at 7.8. Then ICSMA-25-148-01 in May, an out-of-bounds read, CVE-2025-5307. Michael Heinzl reported both.
Out-of-bounds reads and writes belong to the family of memory-safety defects that appear when software copies or indexes data without first confirming it fits the buffer set aside for it. Image and file parsers are fertile ground for them because a format like DICOM carries many length fields, offsets and nested structures, each one trusted to describe the bytes that follow. A single malformed value can steer the reader past the end of its allocation.
The two findings differ in a way that matters to a defender. An out-of-bounds read can leak whatever sits in adjacent memory, while an out-of-bounds write can corrupt program state and, in the worst case, let an attacker redirect execution. On a radiology workstation that opens studies arriving from many sources, either outcome puts the machine reading diagnostic images at the mercy of the file it was asked to display.
Open a crafted DCM file, corrupt memory, and in the write case that is a path to code execution on the workstation. When one memory-corruption bug turns up in a file parser, more are usually nearby, because the code was written without a hostile-input mindset throughout. A single fuzzing campaign against the DICOM parser would likely have surfaced both, and that campaign is cheaper than two advisories.
Advisories landing a few months apart also show how researchers work a promising target. Code that yields one memory-corruption bug invites a closer look, and the same investigator often returns with fresh test cases against the same parser. For imaging departments the practical effect is a widely used viewer that needed attention twice in a single season, a rhythm that wears on teams already stretched by the volume of medical-device advisories.