Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Navicat navicat For Oracle
|
|
| CPEs | cpe:2.3:a:navicat:navicat_for_oracle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Navicat navicat For Oracle
|
Mon, 30 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash. | |
| Title | Navicat for Oracle 12.1.15 Password Field Denial of Service | |
| First Time appeared |
Navicat
Navicat navicat |
|
| Weaknesses | CWE-620 | |
| CPEs | cpe:2.3:a:navicat:navicat:12.1.15:*:*:*:*:*:*:* | |
| Vendors & Products |
Navicat
Navicat navicat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-30T13:53:07.017Z
Reserved: 2026-03-30T10:55:24.174Z
Link: CVE-2019-25653
Updated: 2026-03-30T13:52:57.239Z
Status : Analyzed
Published: 2026-03-30T12:16:17.953
Modified: 2026-04-08T16:31:18.803
Link: CVE-2019-25653
No data.
OpenCVE Enrichment
Updated: 2026-04-08T20:00:39Z