Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-5442 A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (U… Orthanc 1.12.11+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5443 A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication f… Orthanc 1.12.11+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-5445 An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used f… Orthanc 1.12.11+ Fix from $2,3002026-04-09 HIGH 7.5 CVE-2026-5440 A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directl… Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.1 CVE-2026-5441 An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, whic… Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.1 CVE-2026-5444 A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, imag… Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5437 An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, th… Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5438 A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits … Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5439 A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and tru… Orthanc 1.12.11+ Fix from $1,9502026-04-09 CRITICAL 9.8 CVE-2025-0896 Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorize… Orthanc 1.5.8+ Fix from $2,3002025-02-13 MEDIUM 6.1 CVE-2024-22725 Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's er… Orthanc 1.12.2+ Fix from $1,6002024-01-24 MEDIUM 6.1 CVE-2023-7238 A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability get… Osimis Web Viewer Mitigation only Fix from $1,6002024-01-23 HIGH 8.8 CVE-2023-33466 Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific depl… Orthanc 1.12.0+ Fix from $1,9502023-06-29