CVE-2019-25559

SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nsasoft:spotpaltalk:1.1.5:*:*:*:*:*:*:*

History

16 Apr 2026, 17:59

Type Values Removed Values Added
References () http://www.nsauditor.com - () http://www.nsauditor.com - Product
References () https://www.exploit-db.com/exploits/46822 - () https://www.exploit-db.com/exploits/46822 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/spotpaltalk-name-key-field-denial-of-service - () https://www.vulncheck.com/advisories/spotpaltalk-name-key-field-denial-of-service - Third Party Advisory
Summary
  • (es) SpotPaltalk 1.1.5 contiene una vulnerabilidad de denegación de servicio en el campo de entrada del código de registro que permite a atacantes locales provocar un fallo en la aplicación al enviar una cadena excesivamente larga. Los atacantes pueden pegar un búfer de 1000 caracteres en el campo Nombre/Clave durante el registro para provocar un fallo cuando se hace clic en el botón Aceptar.
First Time Nsasoft spotpaltalk
Nsasoft
CPE cpe:2.3:a:nsasoft:spotpaltalk:1.1.5:*:*:*:*:*:*:*

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-04-16 17:59


NVD link : CVE-2019-25559

Mitre link : CVE-2019-25559

CVE.ORG link : CVE-2019-25559


JSON object : View

Products Affected

nsasoft

  • spotpaltalk
CWE
CWE-1260

Improper Handling of Overlap Between Protected Memory Ranges