CVE-2019-25553

CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cewe:photo_importer:6.4.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-21 13:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25553

Mitre link : CVE-2019-25553

CVE.ORG link : CVE-2019-25553


JSON object : View

Products Affected

cewe

  • photo_importer
CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse