CVE-2019-25657

Severity CVSS v4.0:
MEDIUM
Type:
CWE-226 Sensitive Information in Resource Not Removed Before Reuse
Publication date:
05/04/2026
Last modified:
20/04/2026

Description

AnyBurn 4.3 x86 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the image conversion function. Attackers can paste a large buffer into the source or destination image file fields and click Convert Now to trigger a crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anyburn:anyburn:*:*:*:*:*:*:x86:* 4.3 (including)