NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash the application by supplying oversized input. Attackers can paste a malicious buffer of 512 bytes into the 'Add a website or keyword to be filtered' field and trigger a crash when removing the created block.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spytech-web
Spytech-web netaware |
|
| CPEs | cpe:2.3:a:spytech-web:netaware:1.20:*:*:*:*:*:*:* | |
| Vendors & Products |
Spytech-web
Spytech-web netaware |
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infiltration-systems
Infiltration-systems netaware |
|
| Vendors & Products |
Infiltration-systems
Infiltration-systems netaware |
Sat, 21 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash the application by supplying oversized input. Attackers can paste a malicious buffer of 512 bytes into the 'Add a website or keyword to be filtered' field and trigger a crash when removing the created block. | |
| Title | NetAware 1.20 Denial of Service via Add Block Buffer Overflow | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-21T12:46:50.813Z
Updated: 2026-03-23T16:29:35.322Z
Reserved: 2026-03-21T12:24:03.713Z
Link: CVE-2019-25547
Updated: 2026-03-23T16:29:31.651Z
Status : Analyzed
Published: 2026-03-21T13:16:16.573
Modified: 2026-03-23T17:32:12.490
Link: CVE-2019-25547
No data.