CVE-2019-25554
Severity CVSS v4.0:
MEDIUM
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/03/2026
Last modified:
16/04/2026
Description
Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can trigger a buffer overflow by pasting a large payload into the Name parameter when adding a preset in the Video/Audio Formats options, causing the application to crash when Reset All is clicked.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tomabo:mp4_converter:3.25.22:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



