8.4

CVSS4.0

CVE-2019-25331 - AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow

AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes of padding followed by register overwrite values to compromi…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

6.7

CVSS4.0

CVE-2019-25330 - SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH)

SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trig…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:29 p.m.

6.7

CVSS4.0

CVE-2019-25329 - FTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)

FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwriting Structured Exception Handler (SEH) with malicious input. Attackers can generate a payload of 4108 'A' characters followed by 4 'B' characters and 40 'C' characters to trigger …

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: March 3, 2026, 12:21 a.m.

6.7

CVSS4.0

CVE-2019-25328 - XnConvert 1.82 - Denial of Service

XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to crash the application. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the registration code field to trigger an application crash.

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:29 p.m.

8.4

CVSS4.0

CVE-2019-25327 - Prime95 Version 29.8 build 6 - Buffer Overflow (SEH)

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

8.8

CVSS4.0

CVE-2019-25325 - Thrive Smart Home 1.1 - 'Smart Home' Improper Limitation of a Pathname to a Restricted Directory ('…

Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and gain unauthor…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25324 - RICOH Web Image Monitor 1.09 - HTML Injection

RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-sit…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:29 p.m.

5.1

CVSS4.0

CVE-2019-25323 - Heatmiser Netmonitor 3.03 - HTML Injection

Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and pot…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:29 p.m.

9.3

CVSS4.0

CVE-2019-25322 - Heatmiser Netmonitor 3.03 - Hardcoded Credentials

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:29 p.m.

8.4

CVSS4.0

CVE-2019-25321 - FTP Navigator 8.03 - Stack Overflow (SEH)

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remot…

πŸ“… Published: Feb. 12, 2026, 10:48 p.m. πŸ”„ Last Modified: April 7, 2026, 2:03 p.m.
Total resulsts: 343923
Page 1129 of 34,393
Β« previous page Β» next page
Filters