6283 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25587
BulletProof FTP Server General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to trigger an application crash when saving the configuration.

CVE-2019-25547
NetAware General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash the application by supplying oversized input. Attackers can paste a malicious buffer of 512 bytes into the 'Add a website or keyword to be filtered' field and trigger a crash when removing the created block.

CVE-2019-25475
SQL Server Password Changer Denial of Service Exploit Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.

CVE-2019-25711
SpotFTP Password Recover General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-807 1 PoC

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code.

CVE-2019-25655
Device Monitoring Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1316 1 PoC

Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters through the Tools menu Connect to New Server interface.

CVE-2019-25338
Dokuwiki General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-204 1 PoC

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

CVE-2019-25625
Blob Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1285 1 PoC

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to crash or become unresponsive.

CVE-2019-25550
Encrypt PDF General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog to trigger an application crash when importing PDF files.

CVE-2019-25553
CEWE PHOTO IMPORTER General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-226 1 PoC

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.

CVE-2019-25666
SpotAuditor General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

CVE-2019-25549
VeryPDF PCL Converter General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.

CVE-2019-25624
Liquid Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-606 1 PoC

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

CVE-2019-25632
phpFileManager Web
6.9
MEDIUM
EPSS
0.0%
2019 CWE-306 1 PoC

phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.

CVE-2019-25557
TwistedBrush Pro Studio General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-775 1 PoC

TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application crash.

CVE-2019-25589
ZOC Terminal General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a crafted payload into the Shell configuration field and trigger a crash when accessing the Command Shell feature.

CVE-2019-25586
Deluge General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-466 1 PoC

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash.

CVE-2019-25561
Lyric Maker General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Title field. Attackers can paste a 5000-byte buffer into the Title input field and save the file to trigger a denial of service condition.

CVE-2019-25677
WinRAR General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-379 1 PoC

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.

CVE-2019-25551
Sandboxie General
6.9
MEDIUM
EPSS
0.0%
2019 CWE-1282 1 PoC

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

CVE-2019-25598
HeidiSQL Portable Database
6.9
MEDIUM
EPSS
0.0%
2019 CWE-787 1 PoC

HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer overflow payload into the password input during Microsoft SQL Server login to trigger an application crash.