Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nsasoft
Nsasoft spotpaltalk |
|
| CPEs | cpe:2.3:a:nsasoft:spotpaltalk:1.1.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsasoft
Nsasoft spotpaltalk |
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nsauditor
Nsauditor spotpaltalk |
|
| Vendors & Products |
Nsauditor
Nsauditor spotpaltalk |
Sat, 21 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked. | |
| Title | SpotPaltalk 1.1.5 Name/Key Field Denial of Service | |
| Weaknesses | CWE-1260 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-23T16:23:09.891Z
Reserved: 2026-03-21T12:29:55.973Z
Link: CVE-2019-25559
Updated: 2026-03-23T16:23:06.874Z
Status : Analyzed
Published: 2026-03-21T13:16:18.777
Modified: 2026-04-16T17:59:31.790
Link: CVE-2019-25559
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:47:24Z