NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasa
Nasa openvsp |
|
| Vendors & Products |
Nasa
Nasa openvsp |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface. | |
| Title | NASA openVSP 3.16.1 Denial of Service via Buffer Overflow | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-25T14:15:13.261Z
Updated: 2026-05-25T14:15:13.261Z
Reserved: 2026-05-25T13:29:39.251Z
Link: CVE-2018-25367
No data.
Status : Received
Published: 2026-05-25T15:16:19.463
Modified: 2026-05-25T15:16:19.463
Link: CVE-2018-25367
No data.