← back
CVE-2019-25667mediumCWE-787

TaskInfo 8.2.0.280 Denial of Service Buffer Overflow

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.9epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
Iarsn · TaskInfo
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.