CVE-2020-37215
Severity CVSS v4.0:
MEDIUM
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/02/2026
Last modified:
12/02/2026
Description
MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash.
Impact
Base Score 4.0
4.60
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH



