Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 30 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection configuration to trigger an application crash. | |
| Title | Navicat for Oracle 12.1.15 Password Field Denial of Service | |
| First Time appeared |
Navicat
Navicat navicat |
|
| Weaknesses | CWE-620 | |
| CPEs | cpe:2.3:a:navicat:navicat:12.1.15:*:*:*:*:*:*:* | |
| Vendors & Products |
Navicat
Navicat navicat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-30T11:02:27.002Z
Reserved: 2026-03-30T10:55:24.174Z
Link: CVE-2019-25653
No data.
Status : Awaiting Analysis
Published: 2026-03-30T12:16:17.953
Modified: 2026-03-30T13:26:07.647
Link: CVE-2019-25653
No data.
OpenCVE Enrichment
No data.
Weaknesses