VYPR

Vendor CVEs

Nsasoft

All CVEs

36 total · sorted by risk
  • CVE-2020-37119CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute…

  • CVE-2018-25213HigMar 26, 2026
    risk 0.55cvss 8.4epss 0.00

    Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode…

  • CVE-2019-25336HigFeb 12, 2026
    risk 0.55cvss 8.4epss 0.00

    SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured…

  • CVE-2019-25434HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field…

  • CVE-2019-25340HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application…

  • CVE-2020-37212HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37211HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37210HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

  • CVE-2020-37209HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37208HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

  • CVE-2020-37207HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

  • CVE-2020-37206HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field.

  • CVE-2020-37205HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an…

  • CVE-2020-37204HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

  • CVE-2020-37201HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

  • CVE-2020-37200HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an…

  • CVE-2020-37199HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

  • CVE-2020-37197HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an…

  • CVE-2020-37196HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger…

  • CVE-2020-37130HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the…

  • CVE-2021-47895HigJan 23, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it into the Event Description field to…

  • CVE-2021-47815HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash.

  • CVE-2021-47814HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.00

    NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential…

  • CVE-2019-25712MedApr 12, 2026
    risk 0.40cvss 6.2epss 0.00

    BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in…

  • CVE-2019-25711MedApr 12, 2026
    risk 0.40cvss 6.2epss 0.00

    SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field,…

  • CVE-2019-25666MedApr 5, 2026
    risk 0.40cvss 6.2epss 0.00

    SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

  • CVE-2019-25597MedMar 22, 2026
    risk 0.40cvss 6.2epss 0.00

    NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function…

  • CVE-2019-25596MedMar 22, 2026
    risk 0.40cvss 6.2epss 0.00

    SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input…

  • CVE-2019-25334MedFeb 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Product Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow…

  • CVE-2020-37131MedFeb 5, 2026
    risk 0.40cvss 6.2epss 0.00

    Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the…

  • CVE-2019-25559MedMar 21, 2026
    risk 0.36cvss 5.5epss 0.00

    SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during…

  • CVE-2021-27722MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering.

  • CVE-2024-0772MedJan 22, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. Local access is required to…

  • CVE-2024-0771MedJan 21, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack…

  • CVE-2024-1185LowFeb 2, 2024
    risk 0.21cvss 3.3epss 0.00

    A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The…

  • CVE-2024-1184LowFeb 2, 2024
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to denial of service. It is possible to launch the attack on the…