6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25553
CEWE PHOTO IMPORTER General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.

CVE-2019-25621
Pixel Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25469
Folder Lock General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local attackers to crash the application by submitting an oversized payload. Attackers can paste a 6000-byte buffer of arbitrary data into the 'Serial Number and Registration Key' field to trigger a denial of service condition.

CVE-2019-25546
NetAware General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.

CVE-2019-25677
WinRAR General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-379 1 PoC

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.

CVE-2019-25545
Terminal Services Manager General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

CVE-2019-25597
NSauditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition.

CVE-2019-25557
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-775 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application crash.

CVE-2019-25598
HeidiSQL Portable Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer overflow payload into the password input during Microsoft SQL Server login to trigger an application crash.

CVE-2019-25561
Lyric Maker General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Title field. Attackers can paste a 5000-byte buffer into the Title input field and save the file to trigger a denial of service condition.

CVE-2019-25476
Outlook Password Recovery Denial of Service Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25251
VidiU Pro Web Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-918 2 PoCs

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.

CVE-2019-25711
SpotFTP Password Recover General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code.

CVE-2019-25463
SpotIE Internet Explorer Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a buffer overflow and crash the application.

CVE-2019-25338
Dokuwiki General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-204 1 PoC

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

CVE-2019-25620
Tree Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-168 1 PoC

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25659
ASPRunner Professional General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

CVE-2019-25588
BulletProof FTP Server Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

CVE-2019-25624
Liquid Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-606 1 PoC

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.