3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-25597
NSauditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.

CVE-2019-25621
Pixel Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25667
TaskInfo General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

CVE-2019-25476
Outlook Password Recovery Denial of Service Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25463
SpotIE Internet Explorer Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a buffer overflow and crash the application.

CVE-2019-25551
Sandboxie General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

CVE-2019-25553
CEWE PHOTO IMPORTER General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.

CVE-2019-25594
ASPRunner.NET General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVE-2019-25620
Tree Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-168 1 PoC

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25666
SpotAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

CVE-2019-25659
ASPRunner Professional General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

CVE-2019-25549
VeryPDF PCL Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.

CVE-2019-25565
Magic Iso Maker General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows local attackers to crash the application by submitting an oversized input. Attackers can generate a file containing 5000 bytes of data, paste it into the Serial Code field during registration, and trigger a denial of service condition that crashes the application.

CVE-2019-25599
Backup Key Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-466 1 PoC

Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form.

CVE-2019-25484
WinMPG iPod Convert General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG iPod Convert 3.0 contains a buffer overflow vulnerability in the Register dialog that allows local attackers to crash the application by supplying an oversized payload. Attackers can paste a large string of characters into the User Name and User Code field to trigger a denial of service condition.

CVE-2019-25660
LanHelper General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service condition.

CVE-2019-25624
Liquid Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-606 1 PoC

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25617
Ease Audio Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 2 PoCs

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interface to trigger an application crash.

CVE-2019-25584
RarmaRadio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an application crash.

CVE-2019-25569
RealTerm: Serial Terminal General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH overwrite values and paste it into the Port field to cause denial of service.