CVE-2019-25557
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application crash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-775
- Published
- 2026-03-21
- Last modified
- 2026-03-23
Affected products
- Pixarra TwistedBrush Pro Studio
Weakness type
Related vulnerabilities
- CVE-2026-78408 — Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
- CVE-2026-45287 — OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2025-13751 — Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on...
- CVE-2025-53476 — A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3...
- CVE-2017-8452 — Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be...