CVE-2019-25553
Severity CVSS v4.0:
MEDIUM
Type:
CWE-226
Sensitive Information in Resource Not Removed Before Reuse
Publication date:
21/03/2026
Last modified:
21/03/2026
Description
CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM



