Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch. | |
| Title | Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow | |
| First Time appeared |
Orthanc
Orthanc dicom Server |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:a:orthanc:dicom_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Orthanc
Orthanc dicom Server |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-02T12:23:36.816Z
Reserved: 2026-06-01T10:22:24.098Z
Link: CVE-2026-10528
Updated: 2026-06-02T12:23:32.244Z
Status : Deferred
Published: 2026-06-02T00:16:36.990
Modified: 2026-06-02T13:03:31.153
Link: CVE-2026-10528
No data.
OpenCVE Enrichment
Updated: 2026-06-02T02:00:13Z