Medium severity6.2NVD Advisory· Published Mar 21, 2026· Updated Apr 10, 2026
CVE-2019-25553
CVE-2019-25553
Description
CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.
Affected products
1- cpe:2.3:a:cewe:photo_importer:6.4.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/46862nvdExploitVDB Entry
- www.vulncheck.com/advisories/cewe-photo-importer-denial-of-service-via-malformed-imagenvdThird Party Advisory
- cewe-photoworld.comnvdProduct
News mentions
0No linked articles in our index yet.