CVE-2018-25253

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:compuphase:termite:*:*:*:*:*:*:*:*

History

27 Apr 2026, 13:24

Type Values Removed Values Added
First Time Compuphase
Compuphase termite
CPE cpe:2.3:a:compuphase:termite:*:*:*:*:*:*:*:*
References () https://www.compuphase.com - () https://www.compuphase.com - Product
References () https://www.compuphase.com/software_termite.htm - () https://www.compuphase.com/software_termite.htm - Product
References () https://www.exploit-db.com/exploits/45453 - () https://www.exploit-db.com/exploits/45453 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/termite-denial-of-service-via-settings-buffer-overflow - () https://www.vulncheck.com/advisories/termite-denial-of-service-via-settings-buffer-overflow - Third Party Advisory

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-27 13:24


NVD link : CVE-2018-25253

Mitre link : CVE-2018-25253

CVE.ORG link : CVE-2018-25253


JSON object : View

Products Affected

compuphase

  • termite
CWE
CWE-787

Out-of-bounds Write