CVE-2026-10528
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file Orthanc
CVSS
3.3
Low
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Jun 2, 2026 · Last modified: Jul 22, 2026 · CWE-119 · CWE-121
0.1%EPSS · 30 days0.1%
2026-06-302026-07-22
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.
- orthanc.uclouvain.behttps://orthanc.uclouvain.be/bugs/attachment.cgi?id=150
- orthanc.uclouvain.behttps://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258
- orthanc.uclouvain.behttps://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258#c4
- orthanc.uclouvain.behttps://orthanc.uclouvain.be/hg/orthanc/rev/bae99026ca97
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10528
- vuldb.comhttps://vuldb.com/submit/820766
- vuldb.comhttps://vuldb.com/vuln/367636
- vuldb.comhttps://vuldb.com/vuln/367636/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-648318.8 HIG—
——0FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.16hCVE-2026-613917.2 HIG—
——0There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.16hCVE-2026-16418—12.7%
——4Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-591449.8 CRI8.7%
——3Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq.
The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq does memcpy(out, ring_slot(h, seq), elem_size) with elem_size read raw from the mmap'd segment, copying into a fixed 8-byte destination scalar. An elem_size larger than 8 bytes writes past the destination.
A local peer that can write the backing file can leave the header valid while setting a large elem_size, so the next read copies a file-controlled length into the fixed 8-byte stack buffer, corrupting adjacent stack frames.16hCVE-2026-164129.8 CRI25.3%
——8Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.16hCVE-2026-164119.8 CRI25.3%
——8Memory safety bugs present in Thunderbird 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.16h