Impact
HeidiSQL Portable 10.1.0.5464 contains a buffer overflow in the password field used for Microsoft SQL Server authentication. Supplying an excessively long password string overwrites memory, causing the application to crash. The failure only terminates the HeidiSQL process; there is no disclosure of data or compromise of the underlying operating system.
Affected Systems
The vulnerable product is HeidiSQL Portable version 10.1.0.5464 provided by Heidisql. The flaw is triggered when a user opens the Microsoft SQL Server login dialog and enters a string that exceeds the expected length in the password field.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires local access and user interaction; it is not remotely exploitable. The impact is a denial of service for the local user, with no effect on confidentiality or integrity.
OpenCVE Enrichment