Nsauditor Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Nsauditor products.
Products
- Nsauditor4 vulnerabilities
- Backup Key Recovery2 vulnerabilities
- SpotAuditor2 vulnerabilities
- BlueAuditor1 vulnerability
- DNSS Domain Name Search Software1 vulnerability
- FTP Password Recover1 vulnerability
- NBMonitor1 vulnerability
- NetShareWatcher1 vulnerability
- Nsauditor Local SEH Buffer Overflow1 vulnerability
- Nsauditor RemShutdown1 vulnerability
- Product Key Explorer1 vulnerability
- SpotFTP Password Recover1 vulnerability
- SpotIE Internet Explorer Password Recovery1 vulnerability
- SpotPaltalk1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25733HIGH | NetShareWatcher 1.5.8.0 SEH Buffer OverflowNetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution when the Find function is invoked. CWE-120Jun 4, 2026 | CVSS8.6v4.0 | EPSS0.148% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25712MEDIUM | BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration KeyBlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registration field, causing the application to crash during registration processing. CWE-787Apr 12, 2026 | CVSS6.9v4.0 | EPSS0.201% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25711MEDIUM | SpotFTP Password Recover 2.4.2 Denial of Service via Name FieldSpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash when submitting the registration code. CWE-807Apr 12, 2026 | CVSS6.9v4.0 | EPSS0.205% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25666MEDIUM | SpotAuditor 3.6.7 Denial of Service Buffer OverflowSpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition. CWE-787Apr 5, 2026 | CVSS6.9v4.0 | EPSS0.237% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-25213HIGH | Nsauditor 3.0.28.0 Local SEH Buffer OverflowNsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges. CWE-787Mar 26, 2026 | CVSS8.6v4.0 | EPSS0.247% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25599MEDIUM | Backup Key Recovery 2.2.4 Denial of Service via Name FieldBackup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form. CWE-466Mar 22, 2026 | CVSS6.9v4.0 | EPSS0.123% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25597MEDIUM | NSauditor 3.1.2.0 Denial of Service via Community FieldNSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large payload into the Community field and trigger the Walk function to cause a denial of service condition. CWE-787Mar 22, 2026 | CVSS6.9v4.0 | EPSS0.238% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25596MEDIUM | SpotAuditor 5.2.6 Name Field Denial of ServiceSpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 repeated characters into the Name input during registration to trigger an application crash. CWE-1287Mar 22, 2026 | CVSS6.9v4.0 | EPSS0.192% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25591MEDIUM | DNSS Domain Name Search Software 2.1.8 Denial of ServiceDNSS Domain Name Search Software 2.1.8 contains a buffer overflow vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can trigger a denial of service by pasting a malicious registration code containing 300 repeated characters into the Name/Key field via the Register menu option. CWE-787Mar 22, 2026 | CVSS6.9v4.0 | EPSS0.179% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25559MEDIUM | SpotPaltalk 1.1.5 Name/Key Field Denial of ServiceSpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked. CWE-1260Mar 21, 2026 | CVSS6.8v4.0 | EPSS0.17% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25463MEDIUM | SpotIE Internet Explorer Password Recovery 2.9.5 Key Field DoSSpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a buffer overflow and crash the application. CWE-787Mar 11, 2026 | CVSS6.9v4.0 | EPSS0.132% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37204MEDIUM | RemShutdown 2.9.0.0 - 'Key' Denial of ServiceRemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.383% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37122MEDIUM | SpotFTP-FTP Password Recover 2.4.8 - Denial of ServiceSpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash. CWE-121Feb 6, 2026 | CVSS6.7v4.0 | EPSS0.401% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37131MEDIUM | Product Key Explorer 4.2.2.0 - 'Key' Denial of ServiceNsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash. CWE-120Feb 5, 2026 | CVSS6.7v4.0 | EPSS0.228% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37130MEDIUM | Nsauditor 3.2.0.0 - 'Name' Denial of ServiceNsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field. CWE-120Feb 5, 2026 | CVSS6.7v4.0 | EPSS0.455% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47895MEDIUM | Nsauditor 3.2.2.0 - 'Event Description' Denial of ServiceNsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description field with a large buffer. Attackers can generate a 10,000-character 'U' buffer and paste it into the Event Description field to trigger an application crash. CWE-770Jan 23, 2026 | CVSS6.7v4.0 | EPSS0.308% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47815MEDIUM | Nsauditor 3.2.3 - Denial of Service (PoC)Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash. CWE-120Jan 15, 2026 | CVSS6.7v4.0 | EPSS0.43% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47814MEDIUM | NBMonitor 1.6.8 - Denial of Service (PoC)NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential system instability. CWE-120Jan 15, 2026 | CVSS6.7v4.0 | EPSS0.362% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47813MEDIUM | Backup Key Recovery 2.2.7 - Denial of Service (PoC)Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a large buffer of 256 repeated characters into the registration key field to trigger application instability and potential crash. CWE-120Jan 15, 2026 | CVSS6.7v4.0 | EPSS0.361% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |