1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25251
VidiU Pro Web Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-918 2 PoCs

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.

CVE-2019-25677
WinRAR General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-379 1 PoC

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.

CVE-2019-25620
Tree Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-168 1 PoC

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25644
WinMPG Video Convert Local Dos Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25588
BulletProof FTP Server Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

CVE-2019-25625
Blob Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to crash or become unresponsive.

CVE-2019-25645
WinAVI iPod/3GP/MP4/PSP Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.

CVE-2019-25463
SpotIE Internet Explorer Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a buffer overflow and crash the application.

CVE-2019-25594
ASPRunner.NET General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVE-2019-25476
Outlook Password Recovery Denial of Service Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25598
HeidiSQL Portable Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer overflow payload into the password input during Microsoft SQL Server login to trigger an application crash.

CVE-2019-25648
MyVideoConverter Pro General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration Code' field to trigger a denial of service condition.

CVE-2019-25667
TaskInfo General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25597
NSauditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.

CVE-2019-25545
Terminal Services Manager General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

CVE-2019-25546
NetAware General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.

CVE-2019-25555
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-131 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder dialog to trigger an application crash.

CVE-2019-25469
Folder Lock General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local attackers to crash the application by submitting an oversized payload. Attackers can paste a 6000-byte buffer of arbitrary data into the 'Serial Number and Registration Key' field to trigger a denial of service condition.

CVE-2019-25683
FileZilla General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-532 1 PoC

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.