Total
14854 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-25235 | 1 Networkactiv | 1 Web Server | 2026-06-17 | N/A | 6.2 MEDIUM |
| NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface. | |||||
| CVE-2018-25230 | 1 Eusing | 1 Free Ip Switcher | 2026-06-17 | N/A | 5.5 MEDIUM |
| Free IP Switcher 3.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Computer Name field. Attackers can paste a malicious payload into the Computer Name input field and click Activate to trigger a denial of service condition that crashes the application. | |||||
| CVE-2018-25228 | 1 Netsetman | 1 Netsetman | 2026-06-17 | N/A | 6.2 MEDIUM |
| NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup feature that allows local attackers to crash the application by supplying oversized input. Attackers can create a malicious configuration file with excessive data and paste it into the Workgroup field to trigger a denial of service condition. | |||||
| CVE-2018-25226 | 1 Ftpshell | 1 Ftpshell Server | 2026-06-17 | N/A | 6.2 MEDIUM |
| FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP Accounts interface. | |||||
| CVE-2018-25223 | 1 Ftnapps | 1 Crashmail Ii | 2026-06-17 | N/A | 9.8 CRITICAL |
| Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service. | |||||
| CVE-2018-25222 | 2026-06-17 | N/A | 8.4 HIGH | ||
| SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context. | |||||
| CVE-2018-25221 | 1 Echatserver | 1 Easy Chat Server | 2026-06-17 | N/A | 9.8 CRITICAL |
| EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context. | |||||
| CVE-2018-25220 | 1 Bochs Project | 1 Bochs | 2026-06-17 | N/A | 9.8 CRITICAL |
| Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges. | |||||
| CVE-2018-25219 | 1 Passfab | 1 Excel Password Recovery | 2026-06-17 | N/A | 8.4 HIGH |
| PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that triggers code execution when pasted into the Licensed E-mail and Registration Code field during the registration process. | |||||
| CVE-2018-25218 | 1 Passfab | 1 Rar Password Recovery | 2026-06-17 | N/A | 8.4 HIGH |
| PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail and Registration Code' field during registration to trigger code execution. | |||||
| CVE-2018-25217 | 1 Rttsoftware | 1 Pdf Explorer | 2026-06-17 | N/A | 8.4 HIGH |
| PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields settings dialog processes the malicious input in the Label field. | |||||
| CVE-2018-25216 | 1 Powersoftware | 1 Anyburn | 2026-06-17 | N/A | 6.2 MEDIUM |
| AnyBurn 4.3 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the image file name field. Attackers can paste a 10000-byte payload into the 'Image file name' parameter during the 'Copy disk to Image' operation to trigger a denial of service condition. | |||||
| CVE-2018-25215 | 1 Passfab | 1 Excel Password Recovery | 2026-06-17 | N/A | 5.5 MEDIUM |
| Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration field to trigger a crash when the Register button is clicked. | |||||
| CVE-2018-25214 | 1 Magnetosoft | 1 Megaping | 2026-06-17 | N/A | 6.2 MEDIUM |
| MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload to the Destination Address List field in the Finger function. Attackers can paste a crafted buffer exceeding expected input limits into the vulnerable field and trigger the Start button to cause a denial of service crash. | |||||
| CVE-2018-25213 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 8.4 HIGH |
| Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges. | |||||
| CVE-2018-25212 | 1 Boxoft | 1 Wav To Wma Converter | 2026-06-17 | N/A | 8.4 HIGH |
| Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems. | |||||
| CVE-2018-25211 | 1 Alloksoft | 1 Video Splitter | 2026-06-17 | N/A | 7.8 HIGH |
| Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License Name registration field, and trigger the overflow when the Register button is clicked. | |||||
| CVE-2018-25198 | 2026-06-17 | N/A | 6.2 MEDIUM | ||
| eToolz 3.4.8.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying oversized input buffers. Attackers can create a payload file containing 255 bytes of data that triggers a buffer overflow condition when processed by the application. | |||||
| CVE-2018-25154 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system. | |||||
| CVE-2018-25042 | 1 Bittorrent | 1 Utorrent | 2026-06-17 | 6.8 MEDIUM | 5.0 MEDIUM |
| A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. | |||||
