CVE-2019-25554 - CVE House
Back to Database
Status published Medium CVE-2019-25554

Tomabo MP4 Converter 3.25.22 Denial of Service via Name Field

Vulnerability Description

Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can trigger a buffer overflow by pasting a large payload into the Name parameter when adding a preset in the Video/Audio Formats options, causing the application to crash when Reset All is clicked.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25554

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Alejandra Sánchez

Affected Vendor

Affected Software

MP4 Converter
Vulnerable Versions:
3.25.22

Timeline

Official Publish: March 21st, 2026
Last Modified: March 23rd, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses (CWE)