Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Feb 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sricam:deviceviewer:3.12.0.1:*:*:*:*:-:*:* |
Tue, 24 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sricam
Sricam deviceviewer |
|
| Vendors & Products |
Sricam
Sricam deviceviewer |
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets. | |
| Title | Sricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP Bypass | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:04:00.427Z
Reserved: 2026-02-19T22:16:19.741Z
Link: CVE-2019-25435
Updated: 2026-02-24T15:27:16.085Z
Status : Analyzed
Published: 2026-02-20T23:16:00.247
Modified: 2026-02-26T02:33:51.807
Link: CVE-2019-25435
No data.
OpenCVE Enrichment
Updated: 2026-02-23T14:33:23Z