CVE-2018-25227
Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.21%
- CWE
- CWE-466
- Published
- 2026-03-30
- Last modified
- 2026-03-30
Affected products
- Valentina-Db Valentina Studio
Weakness type
Related vulnerabilities
- CVE-2026-57025 — Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash
- CVE-2018-25234 — SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
- CVE-2019-25599 — Backup Key Recovery 2.2.4 Denial of Service via Name Field
- CVE-2019-25586 — Deluge 1.3.15 Denial of Service via URL Field
- CVE-2019-25548 — BlueStacks 4.80.0.1060 Denial of Service via Search Field
- CVE-2024-33602 — nscd: netgroup cache assumes NSS callback uses in-buffer strings
- CVE-2024-21849 — BIG-IP Websockets vulnerability