SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNsasoft Spotpaltalk
APPNsasoft1.1.5
Related vulnerabilities
Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local at...
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that al...
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attac...
SpotFTP Password Recover 2.4.2 zawiera podatność denial of service pozwalającą lokalnym atakującym na zapaść a...
BlueAuditor 1.7.2.0 zawiera lukę buffer overflow w polu klucza rejestracji, która pozwala lokalnymi atakującym...