Impact
This vulnerability is a classic buffer overflow in the login dialog of CEWE Photoshow 6.3.4. When a user enters an email address or password longer than expected, the application overflows a fixed‑size buffer and crashes. The crash prevents legitimate users from launching the application until it is restarted, resulting in a denial of service. The overflow does not provide a path to execute arbitrary code or gain data access; the impact is limited to availability disruption.
Affected Systems
The affected product is CEWE Photoshow 6.3.4 distributed by Cewe‑Photoworld. No other versions or vendor forks were listed, so the vulnerability appears to be specific to this release.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity, yet the EPSS score is less than 1%, indicating a low probability that attackers are targeting it. It is not listed in CISA’s KEV catalog. An attacker can exploit the weakness by simply launching the application and supplying oversized credentials; no special privileges or network access are required. The attack vector is therefore local or remote application usage, producing a direct denial of service impact.
OpenCVE Enrichment