Top Password Software Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Top Password Software products.
Products
- MSN Password Recovery2 vulnerabilities
- Top Password Firefox Password Recovery1 vulnerability
- Top Password Software Dialup Password Recovery1 vulnerability
- ZIP Password Recovery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37215MEDIUM | MSN Password Recovery 1.30 - Denial of ServiceMSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.231% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37193MEDIUM | ZIP Password Recovery 2.30 - 'ZIP File' Denial of ServiceZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.383% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37192MEDIUM | MSN Password Recovery 1.30 - XML External Entity InjectionMSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information. CWE-611Feb 11, 2026 | CVSS6.7v4.0 | EPSS0.207% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37191MEDIUM | Top Password Software Dialup Password Recovery 1.30 - Denial of ServiceTop Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.282% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37190MEDIUM | Top Password Firefox Password Recovery 2.8 - Denial of ServiceTop Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.282% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |