Filtered by vendor Nsasoft
Subscribe
Total
36 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-0772 | 1 Nsasoft | 1 Sharealarmpro | 2026-06-17 | 4.3 MEDIUM | 5.3 MEDIUM |
| A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251672. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2024-0771 | 1 Nsasoft | 1 Product Key Explorer | 2026-06-17 | 4.3 MEDIUM | 5.3 MEDIUM |
| A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2021-47895 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 7.5 HIGH |
| Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it into the Event Description field to trigger an application crash. | |||||
| CVE-2021-47815 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 7.5 HIGH |
| Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash. | |||||
| CVE-2020-37130 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 7.5 HIGH |
| Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field. | |||||
| CVE-2020-37119 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 9.8 CRITICAL |
| Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefully constructed exploit. | |||||
| CVE-2019-25712 | 1 Nsasoft | 1 Blueauditor | 2026-06-17 | N/A | 6.2 MEDIUM |
| BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the application to crash during registration processing. | |||||
| CVE-2019-25711 | 1 Nsasoft | 1 Spotftp | 2026-06-17 | N/A | 6.2 MEDIUM |
| SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code. | |||||
| CVE-2019-25666 | 1 Nsasoft | 1 Spotauditor | 2026-06-17 | N/A | 6.2 MEDIUM |
| SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition. | |||||
| CVE-2019-25597 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 6.2 MEDIUM |
| NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition. | |||||
| CVE-2019-25596 | 1 Nsasoft | 1 Spotauditor | 2026-06-17 | N/A | 6.2 MEDIUM |
| SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an application crash. | |||||
| CVE-2019-25559 | 1 Nsasoft | 1 Spotpaltalk | 2026-06-17 | N/A | 5.5 MEDIUM |
| SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked. | |||||
| CVE-2019-25340 | 1 Nsasoft | 1 Spotauditor | 2026-06-17 | N/A | 7.5 HIGH |
| SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64 Encrypted Password field. | |||||
| CVE-2019-25336 | 1 Nsasoft | 1 Spotauditor | 2026-06-17 | N/A | 8.4 HIGH |
| SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system. | |||||
| CVE-2019-25334 | 1 Nsasoft | 1 Product Key Explorer | 2026-06-17 | N/A | 6.2 MEDIUM |
| Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow when pasted into the registration name field, causing the application to crash. | |||||
| CVE-2018-25213 | 1 Nsasoft | 1 Nsauditor | 2026-06-17 | N/A | 8.4 HIGH |
| Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges. | |||||
