0.0

CVE-2026-5445 - Out-of-Bounds Read in DicomImageDecoder (DecodeLookupTable)

An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used for `PALETTE COLOR` images does not validate pixel indices against the lookup table size. Crafted images containing indices larger than the palette siz…

πŸ“… Published: April 9, 2026, 2:42 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.

0.0

CVE-2026-5444 - Heap Buffer Overflow in PAM Image Buffer Allocation

A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen values can cause an integer overflow during buffer size calculation, re…

πŸ“… Published: April 9, 2026, 2:42 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.

0.0

CVE-2026-5441 - Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A c…

πŸ“… Published: April 9, 2026, 2:42 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.

5.1

CVSS3.1

CVE-2026-34757 - LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chu…

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_str…

πŸ“… Published: April 9, 2026, 2:41 p.m. πŸ”„ Last Modified: April 9, 2026, 4:07 p.m.

8.2

CVSS3.1

CVE-2026-34578 - OPNsense has an LDAP Injection via Unsanitized Username in Authentication

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field…

πŸ“… Published: April 9, 2026, 2:34 p.m. πŸ”„ Last Modified: April 9, 2026, 6:16 p.m.

9.3

CVSS4.0

CVE-2025-62718 - Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through …

πŸ“… Published: April 9, 2026, 2:31 p.m. πŸ”„ Last Modified: April 10, 2026, 9:32 a.m.

7.5

CVSS4.0

CVE-2026-5959 - GL.iNet GL-RM1/GL-RM10/GL-RM10RC/GL-RM1PE Factory Reset improper authentication

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The complexi…

πŸ“… Published: April 9, 2026, 2:30 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.

0.0

CVE-2026-4116 -

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

πŸ“… Published: April 9, 2026, 2:27 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.

0.0

CVE-2026-4114 -

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

πŸ“… Published: April 9, 2026, 2:25 p.m. πŸ”„ Last Modified: April 10, 2026, 3:56 a.m.

0.0

CVE-2026-4113 -

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

πŸ“… Published: April 9, 2026, 2:23 p.m. πŸ”„ Last Modified: April 10, 2026, 8:53 a.m.
Total resulsts: 343975
Page 51 of 34,398
Β« previous page Β» next page
Filters