CVE-2019-25475
SQL Server Password Changer 1.90 Denial of Service Buffer Overflow
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.
| CWE | CWE-787 |
| Vendor | top-password |
| Product | sql server password changer denial of service exploit |
| Published | Mar 11, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for top-password sql server password changer denial of service exploit
Be the first to know when new medium vulnerabilities affecting top-password sql server password changer denial of service exploit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Top-Password / SQL Server Password Changer Denial of Service Exploit
1.90
References
Credits
Velayutham Selvaraj & Praveen Thiyagarayam (TwinTech Solutions)