CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.
References
Configurations
No configuration.
History
26 Apr 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-26 22:17
Updated : 2026-04-27 18:53
NVD link : CVE-2018-25294
Mitre link : CVE-2018-25294
CVE.ORG link : CVE-2018-25294
JSON object : View
Products Affected
No product.
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
