Security Advisories
Responsible vulnerability disclosures from our security research.
As part of our security research, we identify and responsibly disclose vulnerabilities in software used in healthcare and critical infrastructure. We work closely with vendors to ensure issues are resolved before publication. Each advisory below documents a confirmed vulnerability along with its impact and recommended mitigation.
gematik
German Healthcare Infrastructure
1 Critical1 High1 Medium
gematik
German Healthcare Infrastructure
Orthanc
PACS / DICOM Server
3 Critical6 High
Orthanc
PACS / DICOM Server
Orthanc DICOM Server
Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode)
Orthanc DICOM Server
Heap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions
Orthanc DICOM Server
Out-of-Bounds Read in DICOM Image Decoder (DecodeLookupTable)
Orthanc DICOM Server
Out-of-Bounds Read in DicomStreamReader Meta-Header Parser
Orthanc DICOM Server
Memory Exhaustion via Unbounded Content-Length
Orthanc DICOM Server
Memory Exhaustion via Forged ZIP Metadata
Orthanc DICOM Server
GZIP Decompression Bomb via Content-Encoding Header
Orthanc DICOM Server
Out-of-Bounds Read in DICOM Image Decoder (PMSCT_RLE1 Decompression)
Orthanc DICOM Server
Heap Buffer Overflow in PAM Image Buffer Allocation
OpenMRS
Electronic Medical Record Platform
1 Critical
OpenMRS
Electronic Medical Record Platform
Oviva
ePA Client (Elektronische Patientenakte)
3 High
Oviva
ePA Client (Elektronische Patientenakte)
DCMTK
OFFIS DICOM Toolkit
1 Critical
DCMTK
OFFIS DICOM Toolkit
Robert Koch Institut (RKI)
Metadata Exchange Platform
1 High
Robert Koch Institut (RKI)
Metadata Exchange Platform
