CVE-2019-25550

MEDIUM

Encrypt PDF 2.3 Denial of Service via Buffer Overflow

Title source: cna

Description

Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog to trigger an application crash when importing PDF files.

Exploits (1)

exploitdb WORKING POC
by Alejandra Sánchez · pythondoswindows
https://www.exploit-db.com/exploits/46871

Scores

CVSS v3 6.2
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
Verypdf/Encrypt PDF 2.3
verypdf/encrypt_pdf 2.3
Published Mar 21, 2026
Tracked Since Mar 21, 2026