CVE-2019-25596

SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nsasoft:spotauditor:5.2.6:*:*:*:*:*:*:*

History

17 Jun 2026, 02:32

Type Values Removed Values Added
Summary
  • (es) SpotAuditor 5.2.6 contiene una vulnerabilidad de denegación de servicio en el diálogo de registro que permite a atacantes locales bloquear la aplicación al proporcionar una cadena excesivamente larga en el campo Nombre. Los atacantes pueden pegar un búfer de 300 caracteres repetidos en la entrada Nombre durante el registro para provocar un bloqueo de la aplicación.

23 Mar 2026, 19:51

Type Values Removed Values Added
CPE cpe:2.3:a:nsasoft:spotauditor:5.2.6:*:*:*:*:*:*:*
References () http://spotauditor.nsauditor.com/downloads/spotauditor_setup.exe - () http://spotauditor.nsauditor.com/downloads/spotauditor_setup.exe - Broken Link
References () https://www.exploit-db.com/exploits/46778 - () https://www.exploit-db.com/exploits/46778 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/spotauditor-name-field-denial-of-service - () https://www.vulncheck.com/advisories/spotauditor-name-field-denial-of-service - Third Party Advisory
First Time Nsasoft
Nsasoft spotauditor

22 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 14:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25596

Mitre link : CVE-2019-25596

CVE.ORG link : CVE-2019-25596


JSON object : View

Products Affected

nsasoft

  • spotauditor
CWE
CWE-1287

Improper Validation of Specified Type of Input