Back to CVE List

CVE-2020-37188

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Nsasoft
Product
Nsauditor SpotOutlook

External References

Discussion (0)

Add Comment

No comments yet. Be the first!