Ad

CVE-2019-25464

MEDIUM CVSS 4.0: 6.7 EPSS 0.01%
Updated Mar 11, 2026
Payload
Parameter Value
CVSS 6.7 (MEDIUM)
Type CWE-770 (Allocation Without Limits)
Vendor Payload
Public PoC Yes

InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a denial of service by copying a large payload into the username field and double-clicking to process it, causing the application to crash.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0