1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25711
SpotFTP Password Recover General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code.

CVE-2019-25655
Device Monitoring Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1316 1 PoC

Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters through the Tools menu Connect to New Server interface.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25338
Dokuwiki General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-204 1 PoC

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

CVE-2019-25591
DNSS Domain Name Search Software General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

DNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can trigger a denial of service by pasting a malicious registration code containing 300 repeated characters into the Name/Key field via the Register menu option.

CVE-2019-25625
Blob Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to crash or become unresponsive.

CVE-2019-25550
Encrypt PDF General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog to trigger an application crash when importing PDF files.

CVE-2019-25661
Remote Process Explorer General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.

CVE-2019-25566
TransMac General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.

CVE-2019-25544
Pidgin General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

CVE-2019-25477
RAR Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger an application crash.

CVE-2019-20649
Software Genérico General
6.9
MEDIUM
EPSS
0.4%
2019 1 PoC

NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.

CVE-2019-25592
PHPRunner Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1260 1 PoC

PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the dashboard name field. Attackers can paste a buffer of 10000 characters into the Name field during dashboard creation to trigger an application crash.

CVE-2019-25624
Liquid Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-606 1 PoC

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25474
Easy MP3 Downloader Denial of Service General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file containing 6000 'A' characters and paste the contents into the Unlock Code field during application startup to trigger a denial of service condition.

CVE-2019-25553
CEWE PHOTO IMPORTER General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.

CVE-2019-25595
jetAudio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-469 1 PoC

jetAudio 8.1.7.20702 Basic contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string through the URL input handler. Attackers can trigger the crash by pasting a buffer of 5000 characters into the Open URL dialog, causing the application to terminate abnormally.

CVE-2019-25621
Pixel Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25569
RealTerm: Serial Terminal General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH overwrite values and paste it into the Port field to cause denial of service.

CVE-2019-25623
Luminance Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-641 1 PoC

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the application to become unresponsive or terminate abnormally.