nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25475 CVE-2019-25475
MEDIUM
SQL Server Password Changer 1.90 Denial of Service Buffer Overflow
Record summary
CVE-2019-25475 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SQL Server Password Changer Denial of Service ExploitBrowse Top-Password / SQL Server Password Changer Denial of Service Exploit | CVE List | 1.90 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSQL Server Password Changer 1.90 - Denial of ServiceExploitDB exploitby Velayutham Selvaraj_ Praveen ThiyagarayamNot analyzed1 file
References
3ExploitDB-47318exploit
https://www.exploit-db.com/exploits/47318 VulnCheck Advisory: SQL Server Password Changer 1.90 Denial of Service Buffer OverflowThird-party advisory
https://www.vulncheck.com/advisories/sql-server-password-changer-denial-of-service-buffer-overflow