6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25551
Sandboxie General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

CVE-2019-25583
RarmaRadio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash.

CVE-2019-25683
FileZilla General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-532 1 PoC

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.

CVE-2019-25596
SpotAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1287 1 PoC

SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an application crash.

CVE-2019-25601
UltraVNC Launcher General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of service condition.

CVE-2019-25565
Magic Iso Maker General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows local attackers to crash the application by submitting an oversized input. Attackers can generate a file containing 5000 bytes of data, paste it into the Serial Code field during registration, and trigger a denial of service condition that crashes the application.

CVE-2019-25290
Smartliving SmartLAN/G/SI Web Networking
6.9
MEDIUM
EPSS
0.0%
2019 CWE-918 2 PoCs

Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP requests.

CVE-2019-25571
MediaMonkey Cloud
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.

CVE-2019-25555
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-131 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder dialog to trigger an application crash.

CVE-2019-25648
MyVideoConverter Pro General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration Code' field to trigger a denial of service condition.

CVE-2019-25667
TaskInfo General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

CVE-2019-25566
TransMac General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.

CVE-2019-25544
Pidgin General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

CVE-2019-25584
RarmaRadio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an application crash.

CVE-2019-25477
RAR Password Recovery General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger an application crash.

CVE-2019-25548
BlueStacks General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-466 1 PoC

BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to the search field. Attackers can paste a buffer of 100,000 'A' characters into the search field and trigger a search operation to cause the application to crash.

CVE-2019-25645
WinAVI iPod/3GP/MP4/PSP Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to trigger an application crash.

CVE-2019-25644
WinMPG Video Convert Local Dos Exploit General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25622
Paint Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the application to crash and become unavailable.