PatchSiren

Nsasoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Nsasoft CVE published 2026-02-20

CVE-2019-25434

CVE-2019-25434 is a denial of service vulnerability in SpotAuditor 5.3.1.0. Unauthenticated attackers can crash the application by submitting excessive data in the registration name field. A large string of characters (5000 bytes or more) in the name field during registration triggers an unhandled exception that crashes the application. The vulnerability has a CVSS score of 6.7 and a severity of MEDIUM. T [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37211

CVE-2020-37211 is a denial of service vulnerability in SpotIM 2.2. An attacker can crash the application by inputting a large buffer in the registration name field. A 1000-character payload can be generated and pasted into the 'Name' field to trigger an application crash. The vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The CVE was published on 2026-02-11T21:16:16.673Z and last modified [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37209

CVE-2020-37209 is a denial of service vulnerability in SpotFTP 3.0.0.0. The vulnerability exists in the registration name input field, allowing attackers to crash the application by generating a 1000-character buffer payload and pasting it into the 'Name' field. This vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The CVE was published on 2026-02-11T21:16:16.293Z and last modified on 2026- [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37208

CVE-2020-37208 is a buffer overflow vulnerability in SpotFTP 3.0.0.0 that allows attackers to crash the application via a 1000-character payload in the 'Key' field. This vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The vulnerability was published on February 11, 2026, and last modified on June 29, 2026. The CVE record and NVD detail pages provide more information on this vulnerability.

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37206

CVE-2020-37206 is a medium-severity denial of service vulnerability in ShareAlarmPro, a network access control software developed by Nsasoft. An attacker can exploit this vulnerability by providing an oversized registration key, which causes the application to crash. The vulnerability has a CVSS score of 4.6 and is considered a medium threat. The CVE record was published on February 11, 2026, and last mod [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37205

CVE-2020-37205 is a denial of service vulnerability in RemShutdown 2.9.0.0 that allows attackers to crash the application by overflowing the 'Name' registration field. An attacker can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash. The vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The CVE was published on 2026-02-11T [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37199

CVE-2020-37199 is a denial of service vulnerability in NBMonitor 1.6.6.0. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash. This vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The CVE was published on 2026-02-11T21:16:14.623Z and last modified on 2026-06-29T18:29:45.990Z. The vulnerability affects NBMonitor version 1. [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37197

CVE-2020-37197 is a denial of service vulnerability in Dnss Domain Name Search Software. An attacker can crash the application by providing a specially crafted input that overflows the 'Name' field. This can be achieved by generating a 1000-character buffer payload and pasting it into the registration name field. The vulnerability has a CVSS score of 4.6 and is classified as MEDIUM severity. The CVE was p [truncated]

MEDIUM Nsasoft CVE published 2026-02-11

CVE-2020-37196

CVE-2020-37196 is a denial of service vulnerability in Dnss Domain Name Search Software. An attacker can crash the application by providing an oversized registration key. A 1000-character buffer payload can be generated and pasted into the registration key field to trigger an application crash. This vulnerability has a CVSS score of 4.6 and a severity of MEDIUM. The CVE was published on 2026-02-11T21:16:1 [truncated]