1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25622
Paint Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the application to crash and become unavailable.

CVE-2019-25251
VidiU Pro Web Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-918 2 PoCs

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.

CVE-2019-25588
BulletProof FTP Server Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

CVE-2019-25594
ASPRunner.NET General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVE-2019-25596
SpotAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1287 1 PoC

SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an application crash.

CVE-2019-25290
Smartliving SmartLAN/G/SI Web Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-918 2 PoCs

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVE-2019-25712
BlueAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the application to crash during registration processing.

CVE-2019-25474
Easy MP3 Downloader Denial of Service General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file containing 6000 'A' characters and paste the contents into the Unlock Code field during application startup to trigger a denial of service condition.

CVE-2019-25567
Valentina Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field during server connection attempts, causing a denial of service.

CVE-2019-25556
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the application to crash.

CVE-2019-25618
AdminExpress General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-73 1 PoC

AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cause the application to become unresponsive or crash.

CVE-2019-25644
WinMPG Video Convert Local Dos Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25645
WinAVI iPod/3GP/MP4/PSP Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.

CVE-2019-25648
MyVideoConverter Pro General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration Code' field to trigger a denial of service condition.

CVE-2019-25667
TaskInfo General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

CVE-2019-25555
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-131 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder dialog to trigger an application crash.

CVE-2019-25571
MediaMonkey Cloud
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.

CVE-2019-25601
UltraVNC Launcher General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of service condition.

CVE-2019-25583
RarmaRadio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash.

CVE-2019-25592
PHPRunner Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1260 1 PoC

PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the dashboard name field. Attackers can paste a buffer of 10000 characters into the Name field during dashboard creation to trigger an application crash.