CVE-2020-37188
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Description
SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Nsasoft
Product
Nsauditor SpotOutlook
Discussion (0)
Add Comment
No comments yet. Be the first!