CVE-2018-25227

Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:valentina-db:studio:*:*:*:*:*:*:*:*

History

08 Apr 2026, 18:31

Type Values Removed Values Added
References () https://valentina-db.com/en/ - () https://valentina-db.com/en/ - Product
References () https://valentina-db.com/en/developer/database/download-valentina-database-adk - () https://valentina-db.com/en/developer/database/download-valentina-database-adk - Product
References () https://www.exploit-db.com/exploits/46421 - () https://www.exploit-db.com/exploits/46421 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/valentina-studio-denial-of-service-via-host-parameter - () https://www.vulncheck.com/advisories/valentina-studio-denial-of-service-via-host-parameter - Third Party Advisory
First Time Valentina-db
Valentina-db studio
Summary
  • (es) Valentina Studio 9.0.4 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al proporcionar una cadena excesivamente larga en el campo Host. Los atacantes pueden desencadenar el bloqueo al pegar un búfer de 256 bytes de caracteres repetidos en el parámetro Host durante los intentos de conexión al servidor.
CPE cpe:2.3:a:valentina-db:studio:*:*:*:*:*:*:*:*

30 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 12:16

Updated : 2026-04-08 18:31


NVD link : CVE-2018-25227

Mitre link : CVE-2018-25227

CVE.ORG link : CVE-2018-25227


JSON object : View

Products Affected

valentina-db

  • studio
CWE
CWE-466

Return of Pointer Value Outside of Expected Range