Home

Description

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

PUBLISHED Reserved 2026-04-05 | Published 2026-04-05 | Updated 2026-04-06 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Out-of-bounds Write

Product status

8.2.0.280
affected

Credits

Rafael Pedrero finder

References

www.exploit-db.com/exploits/46314 (ExploitDB-46314) exploit

www.iarsn.com/ (Official Product Homepage) product

www.vulncheck.com/...kinfo-denial-of-service-buffer-overflow (VulnCheck Advisory: TaskInfo 8.2.0.280 Denial of Service Buffer Overflow) third-party-advisory

cve.org (CVE-2019-25667)

nvd.nist.gov (CVE-2019-25667)

Download JSON