Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Valentina-db studio
|
|
| CPEs | cpe:2.3:a:valentina-db:studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Valentina-db studio
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Valentina-db
Valentina-db valentina Studio |
|
| Vendors & Products |
Valentina-db
Valentina-db valentina Studio |
Mon, 30 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts. | |
| Title | Valentina Studio 9.0.4 Denial of Service via Host Parameter | |
| Weaknesses | CWE-466 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-30T11:02:20.479Z
Updated: 2026-03-30T13:39:24.628Z
Reserved: 2026-03-30T10:53:51.466Z
Link: CVE-2018-25227
Updated: 2026-03-30T13:39:21.436Z
Status : Analyzed
Published: 2026-03-30T12:16:15.940
Modified: 2026-04-08T18:31:01.117
Link: CVE-2018-25227
No data.