CVE-2019-25559
SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-1260
- Published
- 2026-03-21
- Last modified
- 2026-03-23
Affected products
- Nsauditor SpotPaltalk
Weakness type
Related vulnerabilities
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors...
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R)...
- CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2019-25602 — GSearch 1.0.1.0 Denial of Service via Search Input
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow