6.7

CVSS3.1

CVE-2026-5165 - Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset

A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system inst…

πŸ“… Published: March 30, 2026, 12:34 p.m. πŸ”„ Last Modified: March 30, 2026, 8:55 p.m.

6.7

CVSS3.1

CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. …

πŸ“… Published: March 30, 2026, 12:34 p.m. πŸ”„ Last Modified: March 30, 2026, 8:55 p.m.

6.9

CVSS4.0

CVE-2019-25655 - Device Monitoring Studio 8.10.00.8925 Denial of Service

Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing re…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:40 p.m.

8.7

CVSS4.0

CVE-2019-25654 - Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an applicatio…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:40 p.m.

6.9

CVSS4.0

CVE-2019-25653 - Navicat for Oracle 12.1.15 Password Field Denial of Service

Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection conf…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:40 p.m.

6.9

CVSS4.0

CVE-2018-25235 - NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS

NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding t…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:41 p.m.

6.9

CVSS4.0

CVE-2018-25234 - SmartFTP Client 9.0.2615.0 Denial of Service via Host Field

SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application …

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 1, 2026, 6:06 p.m.

6.9

CVSS4.0

CVE-2018-25233 - WebDrive 18.00.5057 Denial of Service via Secure WebDAV

WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer-overflow payload of 5000 bytes in the username parame…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 30, 2026, 8:55 p.m.

6.8

CVSS4.0

CVE-2018-25232 - Softros LAN Messenger 9.2 Denial of Service via Log Files Location

Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field. Attackers can input a buffer of 2000 characters in the Log Files Location custom path parameter t…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:41 p.m.

6.9

CVSS4.0

CVE-2018-25231 - HeidiSQL 9.5.0.5196 Denial of Service via Preferences

HeidiSQL 9.5.0.5196 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long file path in the logging preferences. Attackers can input a buffer-overflow payload through the SQL log file path field in Preferences > Logging to tr…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: March 31, 2026, 8:41 p.m.
Total resulsts: 341598
Page 47 of 34,160
Β« previous page Β» next page
Filters