Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasa
Nasa openvsp |
|
| Vendors & Products |
Nasa
Nasa openvsp |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input field within the Geom browser pod addition interface. | |
| Title | NASA openVSP 3.16.1 Denial of Service via Buffer Overflow | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-27T16:09:40.605Z
Reserved: 2026-05-25T13:29:39.251Z
Link: CVE-2018-25367
Updated: 2026-05-27T16:09:35.995Z
Status : Deferred
Published: 2026-05-25T15:16:19.463
Modified: 2026-06-17T01:55:19.620
Link: CVE-2018-25367
No data.
OpenCVE Enrichment
Updated: 2026-05-26T13:00:36Z