CVE-2018-25214

MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload to the Destination Address List field in the Finger function. Attackers can paste a crafted buffer exceeding expected input limits into the vulnerable field and trigger the Start button to cause a denial of service crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:magnetosoft:megaping:1.0:*:*:*:*:*:*:*

History

27 Mar 2026, 18:21

Type Values Removed Values Added
CPE cpe:2.3:a:magnetosoft:megaping:1.0:*:*:*:*:*:*:*
First Time Magnetosoft
Magnetosoft megaping
References () http://www.magnetosoft.com/ - () http://www.magnetosoft.com/ - Product
References () http://www.magnetosoft.com/downloads/win32/megaping_setup.exe - () http://www.magnetosoft.com/downloads/win32/megaping_setup.exe - Product
References () https://www.exploit-db.com/exploits/46004 - () https://www.exploit-db.com/exploits/46004 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/megaping-local-buffer-overflow-denial-of-service - () https://www.vulncheck.com/advisories/megaping-local-buffer-overflow-denial-of-service - Third Party Advisory
Summary
  • (es) MegaPing contiene una vulnerabilidad local de desbordamiento de búfer que permite a atacantes locales provocar la caída de la aplicación al proporcionar una carga útil sobredimensionada al campo Destination Address List en la función Finger. Los atacantes pueden pegar un búfer manipulado que excede los límites de entrada esperados en el campo vulnerable y activar el botón Start para causar una caída por denegación de servicio.

26 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 14:16

Updated : 2026-03-27 18:21


NVD link : CVE-2018-25214

Mitre link : CVE-2018-25214

CVE.ORG link : CVE-2018-25214


JSON object : View

Products Affected

magnetosoft

  • megaping
CWE
CWE-787

Out-of-bounds Write