VYPR

Excel Password Recovery

by Passfab

CVEs (2)

  • CVE-2018-25219HigMar 26, 2026
    risk 0.55cvss 8.4epss 0.00

    PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that triggers code execution when pasted into the Licensed E-mail and Registration Code field during the registration process.

  • CVE-2018-25215MedMar 26, 2026
    risk 0.36cvss 5.5epss 0.00

    Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration field to trigger a crash when the Register button is clicked.