CVE-2018-25368
Published: 25 May 2026
Summary
CVE-2018-25368 is a high-severity Memory Allocation with Excessive Size Value (CWE-789) vulnerability in Nordvpn (inferred from references). Its CVSS base score is 7.5 (High).
Operationally, ranked at the 15.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
NVD Description
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field…
more
to trigger an application crash when attempting to authenticate.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2018-21891