CVE detail
CVE-2026-10528
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/367636/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 2, 2026, 12:16 AM - https://vuldb.com/vuln/367636vuldb.com
No excerpt available.
Exploitvuldb.comJun 2, 2026, 12:16 AM - https://vuldb.com/submit/820766vuldb.com
No excerpt available.
Exploitvuldb.comJun 2, 2026, 12:16 AM - https://vuldb.com/cve/CVE-2026-10528vuldb.com
No excerpt available.
Exploitvuldb.comJun 2, 2026, 12:16 AM - https://orthanc.uclouvain.be/hg/orthanc/rev/bae99026ca97orthanc.uclouvain.be
No excerpt available.
referenceorthanc.uclouvain.beJun 2, 2026, 12:16 AM - https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258#c4orthanc.uclouvain.be
No excerpt available.
referenceorthanc.uclouvain.beJun 2, 2026, 12:16 AM - https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258orthanc.uclouvain.be
No excerpt available.
referenceorthanc.uclouvain.beJun 2, 2026, 12:16 AM - https://orthanc.uclouvain.be/bugs/attachment.cgi?id=150orthanc.uclouvain.be
No excerpt available.
referenceorthanc.uclouvain.beJun 2, 2026, 12:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16248CVSS 7.4 · High
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. Th…
- CVE-2026-16097CVSS 8.7 · High
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 re…
- CVE-2026-16096CVSS 8.7 · High
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads…
- CVE-2026-15701CVSS 8.9 · High
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd.…
- CVE-2026-15696CVSS 7.4 · High
A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument…
- CVE-2026-15695CVSS 7.4 · High
A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument…