Vulnerability Description
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sweetscape | 010 Editor | 9.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/ereisr00/bagofbugz/blob/master/010Editor/SubStr.btExploitThird Party Advisory
- https://www.sweetscape.com/010editor/release_notes.htmlRelease NotesVendor Advisory
- https://github.com/ereisr00/bagofbugz/blob/master/010Editor/SubStr.btExploitThird Party Advisory
- https://www.sweetscape.com/010editor/release_notes.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2019-12555?
CVE-2019-12555 is a vulnerability with a CVSS score of 7.5 (HIGH). In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to cause a denial of servic...
How severe is CVE-2019-12555?
CVE-2019-12555 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12555?
Check the references section above for vendor advisories and patch information. Affected products include: Sweetscape 010 Editor.