CVE-2022-50689
Severity CVSS v4.0:
MEDIUM
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
22/12/2025
Last modified:
31/12/2025
Description
Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cobiansoft:reflector:0.9.93:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



