CVE-2025-27578: Pixmeo Osirix Md

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.

Affected products

  • Pixmeo Osirix Md: up to and including 14.0.1

Published 2025-05-08. Last modified 2026-06-17.